Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Hackers are exploiting a critical vulnerability in Fortinet EMS to deploy remote access tools
Global Security

Hackers are exploiting a critical vulnerability in Fortinet EMS to deploy remote access tools

AdminBy AdminDecember 20, 2024No Comments3 Mins Read
Critical Fortinet EMS Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


December 20, 2024Ravi LakshmananVulnerability / Cyber ​​attack

Critical vulnerability in Fortinet EMS

Fixed a critical security flaw affecting Fortinet FortiClient EMS being exploited by attackers as part of a cyber campaign that installed remote desktop software such as AnyDesk and ScreenConnect.

The vulnerability in question CVE-2023-48788 (CVSS Score: 9.3), a SQL implementation flaw that allows attackers to execute unauthorized code or commands by sending specially crafted data packets.

Russian cybersecurity firm Kaspersky said the October 2024 attack targeted an unnamed company’s Windows server that was exposed to the Internet and had two open ports connected to FortiClient EMS.

Cyber ​​security

“The targeted company uses this technology to allow employees to download specific policies to their corporate devices, giving them secure access to the Fortinet VPN,” it said. said in Thursday’s analysis.

Further analysis of the incident revealed that the threat actors exploited CVE-2023-48788 as the initial access vector, subsequently deleting the ScreenConnect executable to gain remote access to the compromised host.

“After the initial installation, the attackers began to download additional payloads to the compromised system to initiate detection and lateral movement activities, such as enumerating network resources, attempting to obtain credentials, performing security evasion techniques, and generating the following type of save through the AnyDesk remote management tool” , — said Kaspersky.

Some of the other notable tools dropped during the attack are listed below –

  • webbrowserpassview.exe, a password recovery tool that shows passwords saved in Internet Explorer (versions 4.0 – 11.0), Mozilla Firefox (all versions), Google Chrome, Safari, and Opera
  • Mimiket
  • netpass64.exe, password recovery tool
  • netscan.exe, network scanner

The threat actors behind the campaign are believed to have targeted various companies located in Brazil, Croatia, France, India, Indonesia, Mongolia, Namibia, Peru, Spain, Switzerland, Turkey, and the UAE using various ScreenConnect subdomains (such as infinity .screenconnect(.)com).

Cyber ​​security

Kaspersky said that on October 23, 2024. it discovered further attempts to weaponize CVE-2023-48788, this time to execute a PowerShell script hosted on the webhook(.) site domain to “collect responses from vulnerable targets” while scanning a system susceptible to the flaw.

The disclosure comes more than eight months after cybersecurity firm Forescout uncovered a similar campaign that involved exploiting CVE-2023-48788 to deliver the ScreenConnect and Metasploit Powerfun payloads.

“Analysis of this incident helped us establish that the methods currently used by attackers to deploy remote access tools are constantly evolving and becoming more sophisticated,” the researchers said.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.