Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Arctic Wolf documented a full intrusion chain built on this CVE. After bypassing authentication, the threat actor abused EMS's trusted position to push malware to managed endpoints, disguising a credential stealer as a Fortinet update. The payload - delivered as FortiEndpoint_Patch.exe and executed silently through PowerShell - is a MinGW-compiled Windows infostealer Arctic Wolf calls EKZ, capable of extracting saved credentials from Chrome and Firefox, including techniques to defeat Chrome's encrypted password storage. | One Forged Header: Unauthenticated Authentication Bypass in Fortinet FortiClient EMS (CVE-2026-35616) ... the flaw lets a remote, unauthenticated attacker bypass the EMS API's certificate-based authentication and issue privileged requests as if they were a trusted administrator.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An undocumented infostealer delivered via compromised FortiClient EMS VPN scripting workflows. It is disguised as a Fortinet endpoint update, executed through PowerShell and batch scripts, harvests browser-stored data from Chromium-based and Firefox browsers, bypasses encrypted password protections, and exfiltrates credentials, credit card data, addresses, phone numbers, and cookies over HTTP before removing local artifacts.
A Windows infostealer delivered via compromised FortiClient EMS as a fake Fortinet update. It steals saved credentials from Chrome and Firefox and includes techniques to bypass Chrome password protection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.