Security experts are warning about a campaign targeting Fortinet FortiGate firewalls with exposed management interfaces. Researchers at Arctic Wolf believe threat actors are exploiting a zero-day vulnerability to gain unauthorized access, alter configurations, and extract credentials.
The campaign, which began in November 2024, unfolded in four distinct phases:
- Vulnerability Scanning (Nov 16–23, 2024): Threat actors scanned for vulnerable Fortinet firewalls.
- Reconnaissance (Nov 22–27): Attackers conducted automated login/logout activities and unauthorized configuration edits to verify and optimize access.
- SSL VPN Setup (Dec 4–7): Hackers created super admin accounts, modified VPN configurations, and established tunnels using client IPs from VPS hosting providers.
- Lateral Movement (Dec 16–27): Using domain admin credentials obtained during the attack, the threat actors executed DCSync to extract further credentials.
The researchers observed attackers leveraging the jsconsole interface and targeting firmware versions ranging from 7.0.14 to 7.0.16, released between February and October 2024. Activity appeared opportunistic, with automated logins originating from anomalous IP addresses.
During the reconnaissance phase, unauthorized configuration changes included toggling console output settings, likely to confirm access. Later, attackers focused on SSL VPN access, adding accounts to VPN portals and using specific ports like 4433, 59449, and 59450 to establish secure tunnels.
The final phase involved extracting credentials to enable lateral movement within victim environments. Researchers observed the use of the workstation hostname “kali,” indicative of malicious intent. Fortunately, in many cases, threat actors were removed before further escalation.
In light of this campaign, organizations using Fortinet FortiGate firewalls are urged to:
- Disable management interface access on public networks.
- Monitor for unusual jsconsole activity.
- Apply the latest security patches and firmware updates.
This attack comes on the heels of Fortinet’s patch for a critical vulnerability (CVE-2023-27997) in June 2023, highlighting the ongoing risks of exposed and unpatched devices. Organizations must remain vigilant to secure their systems against evolving threats.

















Comments