Fortinet Sounds the Alarm: Threat Actors Maintain Stealth Access to FortiGate Devices Using Old Exploits

Listen to this Post

Fortinet Raises Concerns Over Persistent Post-Exploitation Technique Used by Hackers

In a critical cybersecurity alert, Fortinet has issued urgent warnings to customers about a stealthy post-exploitation method that allows threat actors to maintain read-only access to compromised FortiGate VPN devices—even after known vulnerabilities have been patched. This lingering threat doesn’t stem from a new vulnerability but from artifacts left behind by attackers during previous intrusions. These artifacts grant continued access through a clever manipulation of the device’s file system, evading traditional detection methods.

The issue gained attention after Fortinet began distributing emails with the subject line “Notification of device compromise – FortiGate / FortiOS – Urgent action required,” warning affected users. Marked with a TLP:AMBER+STRICT classification, the communication stressed the severity of the problem.

The exploitation technique hinges on the creation of symbolic links within the language files folder of SSL-VPN-enabled FortiGate devices. This allowed cybercriminals to maintain a read-only bridge to the root file system, persisting access long after the initial attack path was sealed off by patches. Fortinet emphasized that while users might assume updating the firmware fixes the issue, these symbolic links could remain, providing the attackers with a hidden backdoor.

Key Takeaways

  • Fortinet warns customers about a post-exploitation technique that allows read-only access to FortiGate VPN devices.
  • The technique is not based on a new vulnerability but instead uses residual artifacts left after exploiting known vulnerabilities.
  • Symbolic links were covertly planted in folders serving SSL-VPN language files, giving attackers read-only access to root directories.

– Vulnerabilities involved include CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762.

  • The breach enables attackers to access sensitive files and configurations even after devices are updated.
  • CERT-FR disclosed that this tactic has been in use since early 2023 in a wide-reaching campaign affecting devices across France.
  • Fortinet advises immediate firmware updates to FortiOS (7.6.2, 7.4.7, 7.2.11, 7.0.17, 6.4.16) to remove the lingering threat.
  • Administrators are urged to check for configuration anomalies and reset exposed credentials.
  • CERT-FR and CISA recommend full device isolation, resetting secrets, and scanning for lateral movement within affected networks.

What Undercode Say:

Fortinet’s recent advisory reflects a growing reality in the cybersecurity landscape: patching a known vulnerability is no longer the finish line. The revelation that cyber attackers are leveraging symbolic links—an old but effective file system trick—to maintain persistence on FortiGate VPN devices exposes a deeper, more insidious layer of cyber warfare.

Let’s break down the implications of this:

  1. Post-exploitation tactics like this suggest that attackers are no longer just exploiting weaknesses—they’re embedding persistence mechanisms that survive even firmware upgrades. This puts pressure on network admins to go beyond patching and dig into filesystem integrity and residual malware traces.

  2. Read-only access might sound harmless, but in the wrong hands, it’s a treasure chest. Attackers can monitor configurations, harvest network layouts, and prepare for future lateral movement—all while staying undetected.

  3. The use of language files as a hiding spot is particularly clever. These are rarely monitored or scanned during routine maintenance, allowing the symbolic links to evade detection.

  4. The symbolic link method could easily be replicated in other environments where modular file systems are used—suggesting this could be a broader threat beyond Fortinet devices.

  5. The involvement of older CVEs—some dating back to 2022—emphasizes how long adversaries have been in these systems, possibly lying dormant while awaiting the perfect opportunity to re-engage.

  6. CERT-FR’s finding that these attacks have been active since early 2023 indicates a widespread compromise, potentially affecting thousands of organizations globally.

  7. The TLP:AMBER+STRICT label on Fortinet’s communication is unusual in vendor-client interactions, reflecting the urgency and sensitivity of the issue.

  8. It’s also telling that CISA stepped in quickly, urging organizations to report anomalies and highlighting the risk of national-level infrastructure being affected.

  9. This scenario shows the importance of forensic-level incident response. A mere log check won’t suffice—you need to dig deep into file integrity, unauthorized file system changes, and unexplained user activity.

  10. The top 10 MITRE ATT&CK techniques cited near the end of the report serve as a stark reminder: 93% of cyberattacks can be traced to known tactics. It’s not always zero-days—often, it’s a well-placed symbolic link and outdated firmware.

Organizations must start thinking like attackers. If someone had read-only access to your most secure devices for over a year, what would they have learned? More importantly, how would you even know?

Fortinet’s advisory is not just a call to update software—it’s a call to re-evaluate endpoint hygiene, auditing, and threat-hunting protocols. Businesses must now start incorporating residual footprint scanning and behavioral anomaly detection as part of their standard incident response plans.

This alert is a glimpse into the future of persistence-based attacks: silent, long-term, and devastatingly effective.

Fact Checker Results:

  • Fortinet has officially confirmed the persistence technique via symbolic links after older vulnerabilities were exploited.
  • CERT-FR and CISA have independently validated the threat and advised isolation and reconfiguration measures.
  • Firmware updates alone do not guarantee remediation—manual checks are necessary to remove symbolic links and restore device integrity.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.pinterest.com
Wikipedia
Undercode AI

Image Source:

Pexels
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 TelegramFeatured Image