Fortinet Threat Research.
Fortinet Threat Research Blog Official blog feed of Fortinet
- New Campaign Uses Remcos RAT to Exploit Victimson November 8, 2024 at 2:00 pm
See how threat actors have abused Remcos to collect sensitive information from victims and remotely control their computers to perform further malicious acts.
- Threat Campaign Spreads Winos4.0 Through Game Applicationon November 6, 2024 at 2:00 pm
FortiGuard Labs reveals a threat actor spreads Winos4.0, infiltrating gaming apps and targeting the education sector. Learn more.
- Burning Zero Days: Suspected Nation-State Adversary Targets Ivanti CSAon October 11, 2024 at 3:00 pm
A case where an advanced adversary was observed exploiting three vulnerabilities affecting the Ivanti Cloud Services Appliance (CSA). This incident is a prime example of how threat actors chain zero-day vulnerabilities to gain initial access to a victim’s network. Learn more.
- Threat Actors Exploit GeoServer Vulnerability CVE-2024-36401on September 5, 2024 at 1:00 pm
When the GeoServer vulnerability CVE-2024-36401 emerged, the FortiGuard Labs gathered related intelligence. This blog highlights the threat actors and how they exploit and use the vulnerability.
- Emansrepo Stealer: Multi-Vector Attack Chainson September 3, 2024 at 1:00 pm
FortiGuard Labs has uncovered a fresh threat – Emansrepo stealer, which is distributed via multiple attack chains for months. Learn more.
- Ransomware Roundup – Undergroundon August 30, 2024 at 1:00 pm
The Underground ransomware has victimized companies in various industries since July 2023. It encrypts files without changing the original file extension. Learn more.
- Deep Analysis of Snake Keylogger’s New Varianton August 28, 2024 at 1:00 pm
Fortinet’s FortiGuard Labs caught a phishing campaign in the wild with a malicious Excel document attached to the phishing email. Get a deep analysis of the campaign and how it delivers a new variant of Snake Keylogger.
- A Deep Dive into a New ValleyRAT Campaign Targeting Chinese Speakerson August 15, 2024 at 1:00 pm
A technical analysis of the ongoing ValleyRat multi-stage malware campaign’s diverse techniques and characteristics.
- Preparation Is Not Optional: 10 Incident Response Readiness Considerations for Any Organizationon August 13, 2024 at 1:00 pm
Incident response preparation is not optional. Here are ten activities every organization should consider implementing. Read more.
- PureHVNC Deployed via Python Multi-stage Loaderon August 8, 2024 at 1:00 pm
FortiGuard Lab reveals a malware “PureHVNC”, sold on the cybercrime forum, is spreading through a phishing campaign targeting employees via a python multi-stage loader. Learn more.