DEEPDATA is a modular post-exploitation malware family for Windows used to collect sensitive information from compromised systems. Reporting states it was used to weaponize a zero-day credential disclosure vulnerability in Fortinet FortiClient for Windows, allowing theft of VPN credentials from FortiClient process memory. The FortiClient credential-theft capability is implemented through a dedicated plugin that uses msenvico.dll to extract credentials from memory. DEEPDATA is described as gathering a wide range of information from target devices and includes plugins to steal credentials from 18 sources, collect chat data, record audio, and extract browser and Wi-Fi information. Reported credential targets include Baidu Net Disk, OneDrive, KeePass, QQ, Windows, Mail Master, Fox Mail, SquirrelSQL, DBVisualizer, OpenSSH, MobaXterm, WinSCP, SecureCRT, PuTTY, Navicat, DBeaver, Xshell, and Xftp. DEEPDATA has been attributed as a malware family developed by the Chinese state-affiliated threat actor BrazenBamboo, which is assessed to produce tooling for governmental operators rather than necessarily operating it directly. The malware and its infrastructure reportedly overlap with DEEPPOST and a Windows variant of LIGHTSPY, including shared plugin logic, export function names, and C2 infrastructure characteristics. Six DEEPDATA C2 servers were identified using Nginx and Django Rest Framework, with separate ports for operator applications and plugin hosting. The malware was publicly linked to exploitation observed in 2024, and reporting noted that Fortinet had acknowledged the FortiClient issue by December 18, 2024, but had not released a patch at that time. High-confidence indicators from the content include the malware name DEEPDATA, its Windows focus, use of a FortiClient credential-extraction plugin, and the msenvico.dll component associated with extracting FortiClient credentials from process memory.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.