HomeSecurityNCSC: UMBRELLA STAND malware targets FortiGate firewalls

NCSC: UMBRELLA STAND malware targets FortiGate firewalls

The UK’s National Cyber ​​Security Centre (NCSC) has issued an urgent warning about “UMBRELLA STAND”, a new malware targeting FortiGate 100D firewall . The malware is believed to exploit security vulnerabilities to gain and maintain access to critical infrastructure.

UMBRELLA STAND malware Fortinet FortiGate firewalls

The malware adopts techniques reminiscent of the older COATHANGER spyware tool , with clear improvements in obfuscation methods. It includes encrypted strings (AES) and deceptive file names to evade detection by security systems.

See also: Cloudflare Tunnels Abused in New Malware Campaign

Advanced features and suspicious network activity

The UMBRELLA STAND comes equipped with advanced features, including:

  • Remote command execution (remote shell)
  • Configurable beacon frequencies
  • Encrypted communication with command-and-control (C2) server

In fact, it uses a fake TLS header on port 443 to imitate legitimate traffic, without properly completing the handshake, which can be used as an indicator of malicious activity.

Communication with the C2 server is carried out via IP 89.44.194.32 – with the possibility of modification during execution.

Persistence and control even after reboot

Of particular concern are persistence mechanisms after reboot, as the UMBRELLA STAND malware leverages techniques such as ldpreload and modifications to the FortiOS reboot process.

Additionally, the malware uses process injection and impersonation, renaming processes to blend into standard Linux system and making it more difficult for administrators to detect unauthorized activity.

See also: Banana Squad: Malicious GitHub repositories distribute malware

UMBRELLA STAND malware: Combines public tools with obfuscation techniques

According to the NCSC, UMBRELLA STAND malware is often deployed alongside publicly available tools such as BusyBox, tcpdump, nbtscan , and openLDAP, which allow it to:

  • Executing shell commands
  • Network traffic monitoring
  • Conducting reconnaissance activities in compromised environments

Hidden directories, such as /data2/.ztls/, are used to hide its presence, further leveraging FortiOS to hide malicious directories from traditional detection methods.

The NCSC already provides indicators of compromise (IOCs) to identify the threat, including:

  • The known IP address C2: 89.44.194.32
  • Specific file paths and hidden directories

UMBRELLA STAND Indicators of Compromise (IOCs)

TypeDescriptionValues
IPv4C2 Infrastructure89.44.194.32
PathHidden Directory for Actor Tooling/data2/.ztls/
PathPaths Used by Actors/tmp/%d.sv, /data2/tmp/%s.ini

Additionally, YARA rules targeting encrypted strings and injection mechanisms have been included to allow detection even in environments with advanced obfuscation.

See also: AntiDot malware has compromised over 3,775 devices

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

NCSC: Time for vigilance and upgrading security systems

The UMBRELLA STAND malware strongly recommends increased surveillance, implementation of security updates , and regular system checks.

This particular threat demonstrates how even specialized network devices can become targets of multi-layered, targeted cyberattacks, creating new security challenges at every level of digital infrastructure.

NCSC

Since the UMBRELLA STAND malware exploits vulnerabilities to infect firewalls, maintaining a robust security posture is crucial to protecting devices. This includes integrating multiple layers of defense, including intrusion detection and prevention systems (IDPS), network segmentation , and continuous monitoring for suspicious activity.

Additionally, investing in employee training to recognize phishing attempts and other social engineering attacks can further reduce the likelihood of systems being compromised.

By prioritizing strategies proactive defense alongside rapid remediation, organizations can significantly enhance their resilience against such threats and protect their infrastructure from advanced cyber attacks.

Source: gbhackers.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS