More Problems for Fortinet: Critical FortiSIEM Flaw Exploited
Executive Summary
A command injection vulnerability, CVE 2025-64155, in Fortinet FortiSIEM has been disclosed and is under active exploitation from various IP addresses.
Vulnerability Details
Affected Product: Fortinet FortiSIEM
Identifier: CVE-2025-64155
Exploitation Status: Actively Exploited
Risk & Impact
Triage: Immediate patching or mitigation is critical due to active exploitation.
Attack Vector: Command Injection.
Ease of Exploit: High, given active exploitation.
Action Plan
Immediate Action: Apply available patches or upgrade to a secure version.
Workaround: Implement network segmentation and access controls to limit potential damage.
Detection: Monitor network traffic for unusual command execution patterns and review FortiSIEM logs for suspicious activity.
Relevant professional terms
Command Injection
A type of security vulnerability that allows an attacker to execute arbitrary commands on a host operating system.
Exploitation
The act of leveraging a vulnerability to cause unintended or unanticipated behavior in a system or application.
StealC Malware Operators Hacked Through XSS Vulnerability
Executive Summary
Researchers discovered that a cross-site scripting (XSS) vulnerability in the web-based control panel used by StealC malware operators allowed them to observe active sessions and gather intelligence. This vulnerability ironically led to the theft of session cookies from the infrastructure designed for stealing credentials.
Vulnerability Details
Affected Product: StealC malware web-based control panel
Exploitation Status: Actively Exploited by researchers
Risk & Impact
Triage: High - Immediate investigation and patching are required due to active exploitation.
Attack Vector: XSS vulnerability in the web-based control panel.
Ease of Exploit: Easy, given the publicly leaked panel code.
Action Plan
Immediate Action: Apply input validation and output encoding to prevent script injection.
Workaround: Implement a web application firewall (WAF) to detect and block malicious payloads.
Detection: Monitor for unusual activity and prepare to apply vendor patches once released.
Relevant professional terms
Cross-Site Scripting (XSS)
A type of web security vulnerability that allows an attacker to inject malicious scripts into the content of a website, which are then executed by other users.
Malware-as-a-Service (MaaS)
A business model where malware developers provide their malicious software to other cybercriminals in exchange for payment.
This week's cybersecurity landscape saw setbacks for Black Axe and BreachForums, the exposure of a new Copilot attack, and PluggyApe malware targeting Ukraine's armed forces. These events highlight the diverse threats facing organizations and individuals.
Key TTPs
Initial Access: PluggyApe uses instant messaging (Signal, WhatsApp) masquerading as charity organizations to deliver malicious links.
Execution: PluggyApe deploys a PyInstaller executable leading to the installation of a Python-based backdoor.
Defense Evasion: PluggyApe uses obfuscation and anti-analysis checks to avoid execution in virtual environments.
Campaign Analysis
PluggyApe has evolved to use MQTT for C2 communications and retrieves C2 addresses from paste services, enhancing operational security. The BreachForums leak exposed nearly 324,000 users, potentially aiding law enforcement investigations.
Infrastructure: PluggyApe uses WebSocket and MQTT for C2, retrieving addresses from rentry[.]co and pastebin[.]com.
Actionable Intelligence
IPs: N/A
Domains:harthulp-ua[.]com, solidarity-help[.]org
Relevant Terms
C2: Command and Control, refers to the infrastructure and techniques used by attackers to communicate with and control compromised systems.
Mobile-First Social Engineering: A tactic where attackers leverage encrypted mobile apps (Signal, WhatsApp) to build rapport and bypass traditional email security gateways.
UAT 8837, a China-linked APT, is targeting critical infrastructure in North America to gain initial access for espionage. The group is exploiting a Sitecore zero-day vulnerability (CVE-2025-53690) and using open-source tools.
Key TTPs
Initial Access: Exploitation of known Sitecore vulnerability (CVE-2025-53690) via exposed machine keys.
Execution: Utilizes open-source tools like Earthworm, SharpHound, and DWAgent for post-compromise activity.
Defense Evasion: Rapidly cycles through tool variants to evade security product detection and disables RestrictedAdmin for RDP.
Campaign Analysis
UAT 8837 has been active since at least 2025, demonstrating sophisticated tradecraft and likely possessing zero-day exploitation capabilities. The actor exfiltrates DLL-based shared libraries, raising concerns about potential supply chain compromises.
Targeting & Infrastructure
Target Profile: Critical infrastructure sectors in North America.
Infrastructure: Employs open-source tools and custom LOTL tooling for reconnaissance and lateral movement.
Relevant Terms
APT (Advanced Persistent Threat): A sophisticated, long-term cyberattack campaign targeting specific organizations.
Zero-Day Vulnerability: A software vulnerability that is unknown to the vendor and for which no patch is available.
GootLoader, a JavaScript malware loader, employs malformed ZIP archives containing 500-1,000 concatenated archives to evade detection. This technique aims to bypass analysis by standard unarchiving tools, delivering malicious JavaScript payloads.
Key TTPs
Initial Access: SEO poisoning and malvertising to lure victims to compromised websites hosting malicious ZIP archives.
Execution: Exploits the default Windows unarchiver to extract and run the JavaScript malware.
Defense Evasion: Concatenates 500-1,000 ZIP archives and truncates the archive's end of central directory (EOCD) record to evade detection by common unarchiving tools.
Campaign Analysis
The malware uses sophisticated obfuscation mechanisms to evade detection, demonstrating a continuous evolution of delivery methods. Unremoved GootLoader infections can lead to data theft or ransomware deployment.
Targeting & Infrastructure
Target Profile: Users searching for legal templates and business-related documents.
Infrastructure: Compromised WordPress sites hosting malicious ZIP archives.
The DOJ announced that Nicholas Moore pleaded guilty to hacking the U.S. Supreme Court's filing system, as well as systems belonging to AmeriCorps and the Department of Veterans Affairs. Moore accessed these systems using stolen credentials.
The Scheme
TTP 1: Stole credentials to gain unauthorized access.
TTP 2: Accessed the Supreme Court's filing system on 25 different days.
TTP 3: Posted screenshots of accessed information on Instagram.
The Players
Facilitators Arrested:Nicholas Moore
The Consequence
Outcome: Moore pleaded guilty to one misdemeanor count of computer fraud.
Strategic Takeaway
This incident highlights the importance of securing credentials and monitoring access to sensitive systems.
Relevant Terms
Stolen Credentials: Illegally obtained login information, such as usernames and passwords, used to access systems without authorization.
Computer Fraud: A criminal act involving the use of computers to commit deceptive practices for financial or personal gain.
Law enforcement in Ukraine and Germany have identified Oleg Evgenievich Nefedov as the leader of the Black Basta ransomware gang and added him to Interpol's wanted list. The Black Basta group is believed to be responsible for at least 600 ransomware incidents, data theft, and extortion targeting large organizations worldwide.
The Scheme
TTP 1: Gaining access to target networks.
TTP 2: Extracting passwords to accounts from information systems using specialized software.
TTP 3: Breaching internal corporate systems and increasing the privileges of the stolen accounts.
The Players
Threat Actor:Black Basta
Facilitators Arrested: Two individuals in Ukraine.
The Consequence
Outcome: Oleg Nefedov has been added to Europol's "Most Wanted" and Interpol's "Red Notice" lists.
Strategic Takeaway
The identification and pursuit of Black Basta's leader highlights international law enforcement's commitment to disrupting ransomware operations.
Relevant Terms
Ransomware-as-a-Service (RaaS): A business model where ransomware developers lease their ransomware tools to affiliates who conduct attacks.
Double Extortion: A tactic used in ransomware attacks where attackers both encrypt data and threaten to publish it if a ransom is not paid.