
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
Indicators of Compromise
No domains found for this campaign
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
Patch immediately: upgrade FortiOS to 7.6.4, 7.4.9, 7.2.12 or 7.0.18 and above, and FortiSwitchManager to 7.2.7 or 7.0.6 and above, per Fortinet advisory FG-IR-25-084 for CVE-2025-25249.
Reduce exposure: remove the fabric service from external interfaces, or apply a local-in policy dropping inbound UDP traffic on CAPWAP control ports 5246 to 5249.
Hunt for C2 sessions on the FortiOS CLI: diagnose sys session filter daddr 146.103.99.177 and diagnose sys session filter daddr 46.151.29.58, followed by diagnose sys session list.
Hunt for implant artifacts on disk: fnsysctl ls -la /tmp/.i.js and fnsysctl ls -la /tmp/, and check for unauthorized Node.js execution with diagnose sys process list | grep node.
Block and monitor the network indicators: 46.151.29.58 and 146.103.99.177 as PivotC2 nodes, plus 45.138.16.182:9130 and 89.217.174.207:9001 as obfs4proxy Tor bridges.
Deploy detections for the host indicators, including fortirun.bin SHA256 2d338ffc8cc80293575c6800c059e33eb41e967907c20ba7687b2231c50837db, the four stager scripts, the encoded and decoded PivotC2 clients, run.ps1 SHA256 c25a27b506fbae62010caf2abff699df5c94d29f056fa7ccfb5f3170d917c8cb and payload.b64.
Treat any confirmed artifact as full configuration exfiltration: rotate all administrator passwords, SSL-VPN user credentials, LDAP bind secrets, wireless PSKs and IPSec pre-shared keys defined on the appliance, and rotate any credential reused elsewhere in the estate.
Assume internal reconnaissance followed the compromise: review LDAP enumeration, RDP registry changes fDenyTSConnections and DisableRestrictedAdmin, reverse-SSH relays, Chrome and Edge credential access, and svchost.exe injection on hosts reachable from the appliance.
Review egress and cloud logs for Exchange .pst archives uploaded to Wasabi or other S3-compatible buckets, and restrict outbound access from management segments.
Patch the additional vulnerabilities the operator targets: CVE-2024-47575 in FortiManager, CVE-2026-35273 in PeopleSoft Enterprise PeopleTools and CVE-2024-26304 in ArubaOS.
Forward appliance logs to an external collector so the PivotC2 kill command cannot remove local evidence, and re-image rather than clean any device confirmed infected.