Campaigns
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

FortiSwitchManagerFortiGatePivotC2CVE-2025-25249FortiOS
SOCRadar Threat Research Unit identified exploitation of CVE 2025 25249, a heap based buffer overflow in the FortiOS and FortiSwitchManager wireless controller daemon, ongoing since July 2026. The exploit binary fortirun.bin opens a Node.js reverse shell that stages PivotC2, a post exploitation Remote Access Trojan for FortiGate appliances. Over one Transport Layer Security socket it tunnels shells, proxies, port forwarding, scanning and configuration harvesting with credential decryption. Of 30,000 targeted addresses, 178 devices were infected, mostly in the United States, with data exfiltration at two victims. Russian language artifacts point to a Russian speaking cybercrime operator.

Indicators of Compromise

No domains found for this campaign

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

Remediation
  • Patch immediately: upgrade FortiOS to 7.6.4, 7.4.9, 7.2.12 or 7.0.18 and above, and FortiSwitchManager to 7.2.7 or 7.0.6 and above, per Fortinet advisory FG-IR-25-084 for CVE-2025-25249.

  • Reduce exposure: remove the fabric service from external interfaces, or apply a local-in policy dropping inbound UDP traffic on CAPWAP control ports 5246 to 5249.

  • Hunt for C2 sessions on the FortiOS CLI: diagnose sys session filter daddr 146.103.99.177 and diagnose sys session filter daddr 46.151.29.58, followed by diagnose sys session list.

  • Hunt for implant artifacts on disk: fnsysctl ls -la /tmp/.i.js and fnsysctl ls -la /tmp/, and check for unauthorized Node.js execution with diagnose sys process list | grep node.

  • Block and monitor the network indicators: 46.151.29.58 and 146.103.99.177 as PivotC2 nodes, plus 45.138.16.182:9130 and 89.217.174.207:9001 as obfs4proxy Tor bridges.

  • Deploy detections for the host indicators, including fortirun.bin SHA256 2d338ffc8cc80293575c6800c059e33eb41e967907c20ba7687b2231c50837db, the four stager scripts, the encoded and decoded PivotC2 clients, run.ps1 SHA256 c25a27b506fbae62010caf2abff699df5c94d29f056fa7ccfb5f3170d917c8cb and payload.b64.

  • Treat any confirmed artifact as full configuration exfiltration: rotate all administrator passwords, SSL-VPN user credentials, LDAP bind secrets, wireless PSKs and IPSec pre-shared keys defined on the appliance, and rotate any credential reused elsewhere in the estate.

  • Assume internal reconnaissance followed the compromise: review LDAP enumeration, RDP registry changes fDenyTSConnections and DisableRestrictedAdmin, reverse-SSH relays, Chrome and Edge credential access, and svchost.exe injection on hosts reachable from the appliance.

  • Review egress and cloud logs for Exchange .pst archives uploaded to Wasabi or other S3-compatible buckets, and restrict outbound access from management segments.

  • Patch the additional vulnerabilities the operator targets: CVE-2024-47575 in FortiManager, CVE-2026-35273 in PeopleSoft Enterprise PeopleTools and CVE-2024-26304 in ArubaOS.

  • Forward appliance logs to an external collector so the PivotC2 kill command cannot remove local evidence, and re-image rather than clean any device confirmed infected.

Observed Countries11

BD (454)
CA (953)
CL (410)
CO (996)
DO (211)
ES (45)
GB (649)
GR (994)
IL (123)
PR (818)
US (207)