HomeSecurityAPT hackers breach US municipal government via unpatched Fortinet VPN

APT hackers breached US municipal government via unpatched Fortinet VPN

The FBI has issued an alert stating that an APT group has breached a US municipal government network by exploiting vulnerabilities in an unpatched Fortinet VPN. Specifically, the police agency’s alert states the following: “The FBI continues to warn about APT (Advanced Persistent Threat) hackers exploiting vulnerabilities in Fortinet equipment. At least since May 2021, an APT hacking group almost certainly exploited a Fortigate device to access a web server hosting the domain for a US municipal government.”

Read also: FBI/CISA: Beware! APT hackers target Fortinet FortiOS servers

FBI
FBI

The feds discovered the attack in question in May 2021, while government experts said that the malicious actors likely created an account with the username “elie,” aiming to gain persistence on the network.

Additionally, in April, the FBI and CISA jointly issued a warning about attacks carried out by APT hacking groups targeting Fortinet FortiOS serversusing multiple exploits.

See also: Hackers "hit" the Belgian Ministry of the Interior!

APT hackers - US municipal government - unpatched Fortinet VPN
APT hackers breached US municipal government via unpatched Fortinet VPN

Malicious actors are actively exploiting the following vulnerabilities in Fortinet FortiOS:

  • CVE-2018-13379
  • CVE-2020-12812
  • CVE-2019-5591

The alert published by the FBI provides technical details about the attack on the US municipal government. Experts noted that the APT group created new user accounts that resembled other existing accounts on the network. The attackers also used the following account usernames:

  • “ellie”
  • "WADGUtilityAccount"

Proposal: FSB: Hackers breached Russian federal agencies

APT hackers - US municipal government - unpatched Fortinet VPN
APT hackers breached US municipal government via unpatched Fortinet VPN

Threat actors may also have made modifications to the Task Scheduler that may appear as unidentified scheduled tasks or “actions.” In the attack analyzed by experts, the hackers have created the “SynchronizeTimeZone”.

The tools associated with this attack are the following:
• Mimikatz (credential theft)
• MinerGate (crypto mining)
• WinPEAS (privilege escalation)
• SharpWMI (Windows Management Instrumentation)
• Enabling BitLocker when not expected (data encryption)
• WinRAR where not expected (archiving)
• FileZilla where not expected (file transfer)

More indicators of compromise are included in the FBI's related warning.

Information source: securityaffairs.co

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS