The UK’s National Cyber Security Centre (NCSC) has issued an urgent warning about “UMBRELLA STAND”, a new malware targeting FortiGate 100D firewall . The malware is believed to exploit security vulnerabilities to gain and maintain access to critical infrastructure.

The malware adopts techniques reminiscent of the older COATHANGER spyware tool , with clear improvements in obfuscation methods. It includes encrypted strings (AES) and deceptive file names to evade detection by security systems.
See also: Cloudflare Tunnels Abused in New Malware Campaign
Advanced features and suspicious network activity
The UMBRELLA STAND comes equipped with advanced features, including:
- Remote command execution (remote shell)
- Configurable beacon frequencies
- Encrypted communication with command-and-control (C2) server
In fact, it uses a fake TLS header on port 443 to imitate legitimate traffic, without properly completing the handshake, which can be used as an indicator of malicious activity.
Communication with the C2 server is carried out via IP 89.44.194.32 – with the possibility of modification during execution.
Persistence and control even after reboot
Of particular concern are persistence mechanisms after reboot, as the UMBRELLA STAND malware leverages techniques such as ldpreload and modifications to the FortiOS reboot process.
Additionally, the malware uses process injection and impersonation, renaming processes to blend into standard Linux system and making it more difficult for administrators to detect unauthorized activity.
See also: Banana Squad: Malicious GitHub repositories distribute malware
UMBRELLA STAND malware: Combines public tools with obfuscation techniques
According to the NCSC, UMBRELLA STAND malware is often deployed alongside publicly available tools such as BusyBox, tcpdump, nbtscan , and openLDAP, which allow it to:
- Executing shell commands
- Network traffic monitoring
- Conducting reconnaissance activities in compromised environments
Hidden directories, such as /data2/.ztls/, are used to hide its presence, further leveraging FortiOS to hide malicious directories from traditional detection methods.
The NCSC already provides indicators of compromise (IOCs) to identify the threat, including:
- The known IP address C2: 89.44.194.32
- Specific file paths and hidden directories
UMBRELLA STAND Indicators of Compromise (IOCs)
| Type | Description | Values |
|---|---|---|
| IPv4 | C2 Infrastructure | 89.44.194.32 |
| Path | Hidden Directory for Actor Tooling | /data2/.ztls/ |
| Path | Paths Used by Actors | /tmp/%d.sv, /data2/tmp/%s.ini |
Additionally, YARA rules targeting encrypted strings and injection mechanisms have been included to allow detection even in environments with advanced obfuscation.
See also: AntiDot malware has compromised over 3,775 devices
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
NCSC: Time for vigilance and upgrading security systems
The UMBRELLA STAND malware strongly recommends increased surveillance, implementation of security updates , and regular system checks.
This particular threat demonstrates how even specialized network devices can become targets of multi-layered, targeted cyberattacks, creating new security challenges at every level of digital infrastructure.

Since the UMBRELLA STAND malware exploits vulnerabilities to infect firewalls, maintaining a robust security posture is crucial to protecting devices. This includes integrating multiple layers of defense, including intrusion detection and prevention systems (IDPS), network segmentation , and continuous monitoring for suspicious activity.
Additionally, investing in employee training to recognize phishing attempts and other social engineering attacks can further reduce the likelihood of systems being compromised.
By prioritizing strategies proactive defense alongside rapid remediation, organizations can significantly enhance their resilience against such threats and protect their infrastructure from advanced cyber attacks.
Source: gbhackers.com
