securityonline.info 14 Sept 2026, 07:13 UTC

Russian Hackers Exploit Fortinet Flaw to Deploy PivotC2 Trojan

Russian Hackers Exploit Fortinet Flaw to Deploy PivotC2 Trojan
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

THE SOCRadar Threat Research Unit says a suspected Russian-speaking cybercrime operator was actively targeting Fortinet edge devices in September 2026. More than 30,000 IP addresses were targeted, with 178 devices confirmed compromised, primarily in the United States. The attackers exploited CVE-2025-25249, described as a critical heap-based buffer overflow in the FortiOS wireless controller service, or CAPWAP control daemon.

Unauthenticated attackers send crafted requests over the service’s UDP port, potentially achieving arbitrary code execution on internet-exposed appliances.

After exploitation, the attackers open a reverse shell and use FortiGate’s native Node.js environment to download and execute the PivotC2 remote access trojan. The malware connects to command servers through an encrypted socket and supports interactive commands, file transfers, port forwarding and proxying into internal networks. Its automated mode can harvest configuration data, decrypt stored administrator and VPN credentials using device-specific keys, extract network details and scan internal IP ranges.

In two observed US intrusions, attackers also enabled remote desktop access, searched for backup and storage systems, dumped computer accounts, stole browser credentials and uploaded email archives to external cloud storage. Russian-language code comments led analysts to associate the activity with a financially motivated group, although the actor’s identity remains unconfirmed.

Fortinet customers should apply the vendor’s patches for CVE-2025-25249 and restrict access to the affected wireless provisioning service where immediate patching is not possible. SOCRadar recommends investigating unexpected Node.js processes or temporary-directory scripts, persistent outbound connections from edge devices and lateral movement originating from firewalls. Confirmed compromise should be treated as a full credential breach, requiring administrator passwords and pre-shared keys to be rotated.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline