UNC5820 is a newly tracked threat cluster associated with exploitation of the Fortinet FortiManager vulnerability CVE-2024-47575. Activity attributed to this cluster was observed as early as June 2024 and involved compromise of internet-exposed FortiManager systems across multiple industries. The actor staged and exfiltrated configuration data from FortiGate devices managed by the compromised FortiManager appliances, including detailed appliance configuration information, user information, and FortiOS256-hashed passwords. The cluster’s observed tradecraft centers on initial access through exploitation of CVE-2024-47575, a critical missing-authentication flaw that can allow arbitrary code or command execution against vulnerable FortiManager devices. Post-compromise activity that has been directly observed includes staging and exfiltration of sensitive management-plane data. The stolen information could enable follow-on compromise of FortiManager, access to managed Fortinet devices, and broader enterprise intrusion, but no confirmed lateral movement, malware deployment, database modification, or broader downstream compromise had been established at the time of reporting. UNC5820 has not been publicly tied at high confidence to a specific country, sponsor, or established intrusion set. Its motivation also remains unassessed based on currently available evidence. The cluster is notable because FortiManager is widely used to administer downstream FortiGate infrastructure, including in managed service provider environments, creating potential for high-impact follow-on access if stolen administrative data is operationalized.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UNC5820 is attributed with exploiting a zero-day vulnerability (CVE-2024-47575) in Fortinet FortiManager devices, leading to confirmed and potential compromises of these devices. The group is believed to have targeted and successfully compromised multiple devices, likely for data exfiltration and credential theft.
UNC5820 is exploiting critical vulnerabilities in FortiManager (CVE-2024-47575 and previously CVE-2024-23113) to exfiltrate configuration data, credentials, and other sensitive information from managed Fortinet devices. The group automates the exfiltration process and could use the stolen data for further compromise or lateral movement within enterprise environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.