Fortinet Threat Research.
Fortinet Threat Research Blog Official blog feed of Fortinet
- Inside The ToolShell Campaignon July 25, 2025 at 1:00 pm
FortiGuard Labs uncovers ToolShell, a sophisticated exploit chain targeting Microsoft SharePoint servers using a mix of patched and zero-day CVEs. Learn how attackers deploy GhostWebShell and KeySiphon for stealthy remote code execution and credential theft.
- In-Depth Analysis of an Obfuscated Web Shell Scripton July 25, 2025 at 1:00 pm
Detailed analysis of an obfuscated web shell used in a CNI attack. Explores its structure, traffic patterns, and Fortinet’s detection and protection.
- A Special Mission to Nowhereon July 23, 2025 at 1:00 pm
Following the Israel-Iran ceasefire, FortiGuard Labs uncovered a phishing campaign posing as a private jet evacuation service from Tel Aviv to New York. Learn how attackers used crisis-driven fear to steal personal and financial data.
- NailaoLocker Ransomware’s “Cheese”on July 18, 2025 at 1:00 pm
FortiGuard Labs analyzes NailaoLocker ransomware, a unique variant using SM2 encryption and a built-in decryption function. Learn how it works, why it matters, and how Fortinet protects against it.
- Improving Cloud Intrusion Detection and Triage with FortiCNAPP Composite Alertson July 17, 2025 at 1:00 pm
FortiCNAPP Composite Alerts link weak signals into clear timelines—helping security teams detect cloud-native threats earlier and triage them faster.
- Old Miner, New Trickson July 16, 2025 at 1:00 pm
FortiCNAPP Labs uncovers Lcrypt0rx, a likely AI-generated ransomware variant used in updated H2Miner campaigns targeting cloud resources for Monero mining.
- How FortiSandbox 5.0 Detects Dark 101 Ransomware Despite Evasion Techniqueson July 14, 2025 at 1:00 pm
Discover how FortiSandbox 5.0 detects Dark 101 ransomware, even with sandbox evasion tactics. Learn how advanced behavioral analysis blocks file encryption, system tampering, and ransom note deployment.
- Catching Smarter Mice with Even Smarter Catson July 10, 2025 at 1:00 pm
Explore how AI is changing the cat-and-mouse dynamic of cybersecurity, from cracking obfuscation and legacy languages to challenging new malware built with Flutter, Rust, and Delphi.
- NordDragonScan: Quiet Data-Harvester on Windowson July 7, 2025 at 1:00 pm
FortiGuard Labs explores how NordDragonScan utilizes an effective distribution network for dissemination. Learn more.
- RondoDox Unveiled: Breaking Down a New Botnet Threaton July 3, 2025 at 1:00 pm
FortiGuard Labs analyzes RondoDox, a stealthy new botnet targeting TBK DVRs and Four-Faith routers via CVE-2024-3721 and CVE-2024-12856. Learn how it evades detection, establishes persistence, and mimics gaming and VPN traffic to launch DDoS attacks.