Recent investigations reveal that a highly advanced threat actor is actively exploiting multiple outdated FortiWebto install the Sliver Command and Control (C2).
See also: Attack underway on Fortinet FortiGate

This campaign highlights a worrying trend in which attackers are leveraging open source offensive tools to maintain a persistent presence on compromised networks, often bypassing traditional defenses. At the heart of the attacks are unpatched edge devices, which become trusted entry points for broader network compromise.
The infection process is primarily based on exploiting vulnerabilities in publicly accessible FortiWeb devices, targeting firmware versions from 5.4.202 to 6.1.62.
Although the exact vulnerability used to breach FortiWeb has not been confirmed, it has been observed that the group is also exploiting the React2Shell (CVE-2025-55182) in other enterprises.
After gaining initial access, the attackers install the Fast Reverse Proxy (FRP), which exposes internal services and creates a direct connection between the victim's internal network and the attackers' external control systems. During regular threat hunting of open directories via Censys, Ctrl-Alt-Int3l analysts identified this malicious infrastructure, discovering exposed Sliver C2 databases and logs.
These exposed data provided rare visibility into the attackers' operational practices, revealing a set of compromised devices that periodically communicated with central command servers.
See also: Fortinet administrators urged to update software to close FortiCloud SSO vulnerabilities

The investigation confirmed that the majority of affected systems were running outdated firmware, making them particularly vulnerable to this opportunistic but targeted campaign.
The operational impact is particularly severe, as it provides the threat actor with long-term and persistent access to critical security devices, which are usually considered trusted within the network. By directly integrating the Sliver implant into the firewall, attackers gain the ability to monitor network traffic and execute commands with elevated privileges.
The campaign also reveals a clear strategic orientation, with specific indications pointing to targets in South Asia, as evidenced by the carefully designed deception infrastructure. The threat actor’s infrastructure is based on decoy domains that mimic legitimate services. Analysis of the C2 settings revealed domains such as ns1.ubunutpackages[.]store and ns1.bafairforce[.]army.
These domains hosted spoofed content, such as an “ Ubuntu Packages ” repository and a “ Bangladesh Airforce ” recruitment page , intended to mislead defenders. This configuration sets the beacon to reconnect every 120 seconds and uses the “ubuntu” pattern to be confused with legitimate Linux processes.
See also: Vulnerability in FortiPAM and FortiSwitch Manager bypasses verification process

The resulting binary is installed in the /bin/.root/system-updater on compromised FortiWeb devices, posing as a system update tool for further concealment.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
