Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Hackers Leverage Compromised Fortinet Devices to Distribute Ransomware

Altszn.com by Altszn.com
January 6, 2023
in Dark Web
0
Hackers Leverage Compromised Fortinet Devices to Distribute Ransomware
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter

[ad_1]

Threat actors have exploited Fortinet Virtual Private Network (VPN) devices to try and infect a Canadian-based college and a global investment firm with ransomware.

The findings come from eSentire’s Threat Response Unit (TRU), which reportedly stopped the attacks and shared information about them with Infosecurity ahead of publication.

eSentire said the threat actors tried to exploit a critical Fortinet vulnerability (tracked CVE-2022-40684) discovered by the company in October 2022.

“Fortinet described the security weakness as an authentication bypass vulnerability. If successfully exploited, an unauthenticated attacker could gain access to a vulnerable Fortinet device.”

In the advisory, Fortinet said they had seen only one incident where the vulnerability was being actively exploited, but a few days later, a functional proof-of-concept (POC) exploit code was publicly released.

“TRU first saw a slew of threat actors scanning the internet for vulnerable Fortinet devices,” eSentire wrote.

Conducting dark web hunts, TRU then said it observed hackers buying and selling compromised Fortinet devices in the underground markets, indicating widespread exploitation.

“Hacker sales ranged from individual organizations to bulk sales, with numerous buyers showing interest,” eSentire explained.

Once they noticed this activity, the team said it tracked down the technical details of the exploit and created log-based detections for Fortinet devices.

“Conducting threat hunts, TRU swept historical logs from the Fortinet devices looking for indicators of compromise,” reads the company’s report. “TRU identified several customers whose devices showed signs of recent threat activity.”

Among that activity were the two aforementioned cyber-intrusions, eSentire said.

“In both cases, once the hackers got a foothold into the targets’ IT environments via the Fortinet VPNs, the threat actors used Microsoft’s remote desktop protocol (RDP) service by abusing trusted Windows processes (also referred to as LOLBINs or living-off-the-land binaries) to achieve lateral movement.”

“The hackers also abused the legitimate encryption utilities, BestCrypt and BitLocker, which were originally intended to secure data – not hold it hostage,” eSentire continued.

According to the advisory, the use of a remote exploit, LOLBINs and legitimate encryption combined with no leak site make attribution difficult.

“However, the ransom note did follow the format of a ransomware observed in early 2022 known as KalajaTomorr,” warned eSentire, “an operation which has been observed deploying BestCrypt via RDP lateral movement.”

Commenting on the exploit is Keegan Keplinger, research and reporting lead for eSentire’s TRU research team. 

“Like any security technology, it is possible to misconfigure an SSL VPN, which can leave [organizations] susceptible to attacks,” said Keplinger.

“VPNs are Internet-facing, so they are easier for hackers to target. What makes them so valuable to threat actors is that VPN devices are often integrated with organization-wide authentication protocols, so access to a VPN device means access to the organization’s credentials.”

The TRU advisory comes a couple of months after the Bahamut spyware group was spotted compromising Android devices via fake VPN apps.

[ad_2]

Read More: news.google.com

Tags: Compromiseddark webDarknetDevicesDistributeFortinetHackersLeverageransomware
ADVERTISEMENT

Recent

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

June 15, 2025
Is it the future of finance?

Is it the future of finance?

June 15, 2025
U.S. Lawmakers Unveil CLARITY Act Regulating Digital Assets

U.S. Lawmakers Unveil CLARITY Act Regulating Digital Assets

June 10, 2025

Categories

  • Bitcoin (4,186)
  • Blockchain (10,075)
  • Crypto (8,000)
  • Dark Web (330)
  • DeFi (7,771)
  • Ethereum (4,174)
  • Metaverse (6,028)
  • Monero (185)
  • NFT (697)
  • Solana (4,785)
  • Web3 (18,810)
  • Zcash (427)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

    VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

    June 15, 2025
    Is it the future of finance?

    Is it the future of finance?

    June 15, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 104,812.00
    • ethereumEthereum (ETH) $ 2,518.23
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.16
    • bnbBNB (BNB) $ 643.25
    • solanaSolana (SOL) $ 145.67
    • usd-coinUSDC (USDC) $ 0.999803
    • tronTRON (TRX) $ 0.274079
    • dogecoinDogecoin (DOGE) $ 0.170182
    • staked-etherLido Staked Ether (STETH) $ 2,516.49
    • cardanoCardano (ADA) $ 0.601204
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 104,812.00
    • hyperliquidHyperliquid (HYPE) $ 38.16
    • wrapped-stethWrapped stETH (WSTETH) $ 3,033.96
    • suiSui (SUI) $ 2.83
    • bitcoin-cashBitcoin Cash (BCH) $ 459.32
    • chainlinkChainlink (LINK) $ 13.11
    • leo-tokenLEO Token (LEO) $ 9.17
    • stellarStellar (XLM) $ 0.250729
    • avalanche-2Avalanche (AVAX) $ 18.01
    • the-open-networkToncoin (TON) $ 2.94
    • whitebitWhiteBIT Coin (WBT) $ 49.39
    • usdsUSDS (USDS) $ 0.999772
    • shiba-inuShiba Inu (SHIB) $ 0.000012
    • wethWETH (WETH) $ 2,517.20
    • wrapped-eethWrapped eETH (WEETH) $ 2,696.87
    • litecoinLitecoin (LTC) $ 84.95
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • hedera-hashgraphHedera (HBAR) $ 0.147543
    • moneroMonero (XMR) $ 314.52
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • polkadotPolkadot (DOT) $ 3.59
    • bitget-tokenBitget Token (BGB) $ 4.31
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 104,794.00
    • uniswapUniswap (UNI) $ 7.53
    • pepePepe (PEPE) $ 0.000010
    • pi-networkPi Network (PI) $ 0.534196
    • aaveAave (AAVE) $ 258.51
    • daiDai (DAI) $ 0.999686
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
    • bittensorBittensor (TAO) $ 359.41
    • okbOKB (OKB) $ 48.86
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • aptosAptos (APT) $ 4.44
    • crypto-com-chainCronos (CRO) $ 0.090682
    • internet-computerInternet Computer (ICP) $ 5.03
    • nearNEAR Protocol (NEAR) $ 2.18
    • jito-staked-solJito Staked SOL (JITOSOL) $ 176.38
    • susdssUSDS (SUSDS) $ 1.06
    • ethereum-classicEthereum Classic (ETC) $ 16.47
    • bitcoinBitcoin (BTC) $ 104,812.00
    • ethereumEthereum (ETH) $ 2,518.23
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.16
    • bnbBNB (BNB) $ 643.25
    • solanaSolana (SOL) $ 145.67
    • usd-coinUSDC (USDC) $ 0.999803
    • tronTRON (TRX) $ 0.274079
    • dogecoinDogecoin (DOGE) $ 0.170182
    • staked-etherLido Staked Ether (STETH) $ 2,516.49
    • cardanoCardano (ADA) $ 0.601204
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 104,812.00
    • hyperliquidHyperliquid (HYPE) $ 38.16
    • wrapped-stethWrapped stETH (WSTETH) $ 3,033.96
    • suiSui (SUI) $ 2.83
    • bitcoin-cashBitcoin Cash (BCH) $ 459.32
    • chainlinkChainlink (LINK) $ 13.11
    • leo-tokenLEO Token (LEO) $ 9.17
    • stellarStellar (XLM) $ 0.250729
    • avalanche-2Avalanche (AVAX) $ 18.01
    • the-open-networkToncoin (TON) $ 2.94
    • whitebitWhiteBIT Coin (WBT) $ 49.39
    • usdsUSDS (USDS) $ 0.999772
    • shiba-inuShiba Inu (SHIB) $ 0.000012
    • wethWETH (WETH) $ 2,517.20
    • wrapped-eethWrapped eETH (WEETH) $ 2,696.87
    • litecoinLitecoin (LTC) $ 84.95
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • hedera-hashgraphHedera (HBAR) $ 0.147543
    • moneroMonero (XMR) $ 314.52
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • polkadotPolkadot (DOT) $ 3.59
    • bitget-tokenBitget Token (BGB) $ 4.31
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 104,794.00
    • uniswapUniswap (UNI) $ 7.53
    • pepePepe (PEPE) $ 0.000010
    • pi-networkPi Network (PI) $ 0.534196
    • aaveAave (AAVE) $ 258.51
    • daiDai (DAI) $ 0.999686
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
    • bittensorBittensor (TAO) $ 359.41
    • okbOKB (OKB) $ 48.86
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • aptosAptos (APT) $ 4.44
    • crypto-com-chainCronos (CRO) $ 0.090682
    • internet-computerInternet Computer (ICP) $ 5.03
    • nearNEAR Protocol (NEAR) $ 2.18
    • jito-staked-solJito Staked SOL (JITOSOL) $ 176.38
    • susdssUSDS (SUSDS) $ 1.06
    • ethereum-classicEthereum Classic (ETC) $ 16.47