Skip to content
.ca
sign in

Threat intelligence from Fortinet

7 reports on cyfar.ca summarizing Fortinet research.

Fortinet6 days ago12 minLLM reportcritical

Multi-Functional Linux Botnet “Evooo1Bot”

Evooo1Bot is a previously undocumented Linux botnet family that extends the publicly leaked Mirai DDoS engine with encrypted C2 communications, SSH brute-force scanning, SOCKS relay functionality, credential sniffing, and an integrated exploit arsenal targeting 19 known vulnerabilities. Active since July 2026, it exploits Internet-facing devices across diverse regions using a loader script at 91.92.40.118/wget.sh. The malware employs multi-layer string obfuscation (AES-256-CTR, ChaCha20, XOR) and anti-analysis checks to evade detection.

Fortinet15 days ago14 minLLM reportmedium

QuickFox Supply Chain Attack Used to Deploy FDMTP Implant

A supply chain attack on the QuickFox VPN/game accelerator application trojanized versions 3.51.0 through 3.59.5 by injecting malicious JavaScript into an Electron renderer HTML file. The JavaScript downloaded an obfuscated loader from a typosquatting domain (cdns3.51quickfox.cn) that enforced execution guardrails before deploying an FDMTP implant via DLL sideloading using a legitimate Microsoft binary (csmonitor.exe). The FDMTP implant established C2 via a custom protocol on ports 20800-20816, collected host information, and supported remote plugin deployment through registry-based storage. Infrastructure remains active and shares technical overlap with the Twill Typhoon threat actor.

Fortinet28 days ago11 minLLM reporthigh

Inside a TrickBot Variant Using DNS Tunneling for C2

FortiGuard Labs identified a TrickBot variant that uses DNS tunneling for C2 communication instead of HTTP, embedding XOR-encrypted data in DNS queries and encoding response payloads within IPv4 address octets. The malware establishes persistence via Windows Task Scheduler disguised as software updates, stores configuration in NTFS Alternate Data Streams, and employs runtime string decryption and hash-based API resolution to evade analysis. Its modular architecture supports process injection (hollowing, doppelgänging), DLL execution via rundll32, PowerShell execution, and raw shellcode execution, retaining the full capability set of the TrickBot family.

Fortinetabout 1 month ago13 minLLM reporthigh

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

A global phishing campaign active since late March 2026 deploys heavily obfuscated JScript droppers that launch LuaJIT or AutoIt-based loaders disguised as TrueType Font (.ttf) files to deliver multiple RATs and infostealers including Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant dubbed Best Private LOGGER. The Lua loader leverages LuaJIT's Foreign Function Interface to call native Windows APIs for in-memory shellcode execution, employing advanced evasion techniques such as decoy memory allocation, Donut header patching, AMSI/ETW bypass, API unhooking, and VEH-based segmented shellcode decryption. The campaign has evolved from October 2025 through June 2026 with progressively more sophisticated anti-analysis capabilities.

Fortinetabout 1 month ago14 minLLM reporthigh

Threat Actors Weaponize AI Hype to Deliver AsyncRAT

Threat actors are weaponizing AI-themed lure documents to deliver a complex multi-stage infection chain culminating in AsyncRAT and a custom .NET RAT called clay_Client. The attack uses hidden LNK files inside compressed archives to initiate a chain of PowerShell scripts that extract, decrypt, and execute payloads from disguised PDF containers using AES-CBC, XOR, and GZip decompression. AutoHotkey scripts perform process hollowing into legitimate .NET Framework executables, while defense evasion includes adding Microsoft Defender exclusions and restoring disabled VBS execution. The final RAT provides full remote control with screen capture, input simulation, fileless assembly loading, and process injection capabilities.

Fortinetabout 1 month ago13 minLLM reporthigh

From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach

The Shai Hulud supply chain worm, attributed to TeamPCP, compromises CI/CD pipelines by injecting malicious npm/PyPI packages that harvest build credentials and pivot into production AWS cloud infrastructure. In a confirmed breach, attackers stole Jenkins EC2 instance role credentials via the Instance Metadata Service (IMDS), used them from external IPs, escalated privileges by creating an IAM user with AdministratorAccess, modified Redshift and Aurora security groups to open network paths, enumerated Secrets Manager for warehouse credentials, and exfiltrated data via the Redshift Data API. The attack demonstrates that pipeline identity equals production identity, with explicit attacker naming conventions (exfil-s3-* policies, exfil STS session names) providing high-fidelity detection opportunities.

Fortinetabout 1 month ago11 minLLM reporthigh

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

FortiGuard Labs identified an ongoing Ousaban banking Trojan campaign targeting users in Spain and Portugal, delivered via phishing PDFs that redirect victims to geofenced malicious webpages. The attack chain involves a VBS script extracting a ZIP payload from a steganographic image, with the final Ousaban EXE establishing persistence via registry Run keys and communicating with C2 servers resolved through daily-changing DDNS hostnames. The malware targets over 25 Spanish and Portuguese financial institutions and employs a custom encryption algorithm shared with the Casbaneiro family to evade detection.