fgfm is a custom implant/backdoor identified on compromised FortiGate devices during Fortinet’s investigation of targeted intrusions exploiting FortiOS path traversal vulnerability CVE-2022-41328. On affected systems, attackers modified the firmware image component /sbin/init to execute /bin/fgfm before the normal boot process, providing persistence. Fortinet assessed the compromises were likely conducted via a FortiManager device in managed environments, with simultaneous compromise of multiple FortiGate firewalls and evidence of FortiManager-delivered script execution. The malware inspects ICMP packets and is triggered by an ICMP packet containing the string ";7(Zu9YTsA7qQ#vm". Upon activation, it extracts an IP address from the packet and establishes a connection back to that address for command and control, functioning similarly to a reverse-connect shell. Reported capabilities include data exfiltration, downloading and writing files, opening a remote shell, and program exit. The activity was described by Fortinet as highly targeted, with indications of a preference for government or government-related organizations and evidence of advanced attacker capability, including reverse engineering of FortiOS. Associated indicators directly mentioned in the content include the file path /bin/fgfm, the modified /sbin/init persistence mechanism, and the ICMP trigger string ";7(Zu9YTsA7qQ#vm".
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The subsequent investigation showed that the attackers modified the device firmware image (/sbin/init) to launch a payload (/bin/fgfm) before the boot process began. This malware allows for data exfiltration, downloading and writing files, or opening remote shells when receiving an ICMP packet containing the ";7(Zu9YTsA7qQ#vm" string.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
smartctl: This file name is the same as the legitimate file /bin/smartctl... Httpsng masquerades itself by running with the process name [ata/0]... Fgfm binary masquerades itself by running with the process name [ata/0]... /bin/smit is a symbolic link to /bin/init (replaced with standalone malicious smit)
Drop /bin/smit binary. It then deletes the existing FortiOS symbolic link of /bin/smit... Drop /bin/toybox... deletes ... /bin/sh ... copies ... /bin/toybox to be the new /bin/sh... fortlinkd... deletes the original /bin/smit binary and replaces it... If the /bin/fgfm file exists, it is removed, and a new malware file is dropped in its place
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom FortiOS implant/backdoor dropped as /bin/fgfm and launched pre-boot via a modified /sbin/init. Supports data exfiltration, file download/write, and remote shell access, with activation/commanding triggered by ICMP packets containing a specific magic string.
Custom FortiGate implant that inspects ICMP packets for a trigger string, extracts an IP address, and initiates a reverse connection to a C2. Supports command execution including data exfiltration, file download/write, and remote shell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.