More than 16,000 Fortinet devices exposed to the internet have been identified as compromised due to a new persistent access method called a “symlink backdoor,” which allows access to sensitive files on already compromised devices.
See also: Critical FortiSwitch vulnerability allows admin passwords to be changed remotely

This revelation comes from threat monitoring platform The Shadowserver Foundation, which initially reported that 14,000 devices.
Today, Piotr Kijewski of Shadowserver told BleepingComputer that the number of affected devices has now risen to 16,620, due to the new persistent access technique that was recently revealed.
Last week, Fortinet warned its customers that it had identified a new persistent access mechanism used by attackers to maintain remote, read-only accessto root filesystem files on FortiGate that had been compromised in the past but have now been patched.
Fortinet said that this issue is not due to the exploitation of new vulnerabilities, but is related to attacks that began in 2023 and continued into 2024. During these attacks, a malicious actor exploited previously unknown vulnerabilities (zero-days) to compromise FortiOS.
Once they gained access to the devices, they created symbolic links within the language files folder that led to the root file system of the SSL-VPN-. Because the language files are publicly accessible on FortiGate devices with SSL-VPN enabled, the attacker could browse to this folder and maintain persistent access to the root file system, even after the initial vulnerabilities were patched.
See also: New SuperBlack ransomware exploits Fortinet vulnerabilities

This month, Fortinet began privately notifying its customers via email about FortiGate devices detected by FortiGuard as compromised via the symlink backdoor.
Fortinet has released an updated AV/IPSthat detects and removes the malicious symbolic link from affected devices. The latest firmware version has also been updated to detect and remove this link. This update also prevents unknown files and folders from being served through the device's built-in web server.
Finally, if a device was found to be compromised, it is possible that attackers had access to the most recent configuration files, including credentials.
For this reason, all credentials should be reset and administrators should follow the remaining steps described in the guide.
See also: Fortinet: Hackers exploit vulnerability in FortiOS and FortiProxy
The use of a symlink backdoor is a sneaky and relatively silent way to maintain access to a system, as it does not rely on active vulnerability exploitation, but on abusing the system file structure. In the case of FortiGate devices, the language files folder became a “gateway” for reading sensitive data, due to its public accessibility when SSL-VPN is enabled. This shows how important it is not only to apply security patches, but also to have constant surveillance and periodic checking of systems for suspicious behavior or unauthorized file modifications.
Source: bleepingcomputer
