Fortinet Threat Research.
FortiGuard Labs Threat Research Official blog feed of Fortinet
- Multi-Functional Linux Botnet “Evooo1Bot”on August 13, 2026 at 1:00 pm
FortiGuard Labs analyzes Evooo1Bot, a modular Linux botnet targeting internet-facing devices with DDoS, SSH attacks, CVE exploits, and SOCKS relays
- QuickFox Supply Chain Attack Used to Deploy FDMTP Implanton August 4, 2026 at 1:00 pm
The FortiGuard Labs Incident Response team analyzes a QuickFox supply chain attack that used trojanized Windows installers, selective targeting, and an evolving FDMTP implant
- Inside a TrickBot Variant Using DNS Tunneling for C2on July 22, 2026 at 1:00 pm
FortiGuard Labs analyzes a TrickBot variant that uses DNS tunneling for C2 communication, modular execution, and employs persistence and obfuscation techniques
- The TTF Trap: A Global Campaign of a Low-Detection Lua Loaderon July 16, 2026 at 1:00 pm
FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.
- Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsulaon July 1, 2026 at 1:00 pm
FortiGuard Labs analyzes a geofenced Ousaban campaign targeting Spain and Portugal with phishing PDFs, steganography, and evasive C2.
- From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breachon June 26, 2026 at 1:00 pm
See how Shai Hulud-linked CI/CD compromise exposed Jenkins credentials, enabled AWS escalation, and led to Redshift breach activity detected by FortiCNAPP
- Threat Actors Weaponize AI Hype to Deliver AsyncRATon June 11, 2026 at 1:00 pm
FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and process injection to deploy AsyncRAT and maintain remote access.
- Cybercriminals Are Targeting the FIFA World Cup 2026on June 4, 2026 at 1:00 pm
FortiGuard Labs research shows how cybercriminals are exploiting the demand for the FIFA World Cup 2026 through phishing, fake tickets, malware, impersonation, and credential theft.
- Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMOon June 3, 2026 at 1:00 pm
FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.
- Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Dataon May 26, 2026 at 1:00 pm
FortiGuard Labs analyzed a new phishing campaign that uses obfuscated JavaScript, PowerShell, process hollowing, and PureLogs to steal sensitive data






