Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
eSentire reported observing threat actors exploiting a flaw in Fortinet FortiClient EMS (CVE-2026-35616, CVSS score: 9.1) to deploy an information stealer called EKZ Stealer against a customer in the energy, utilities, and waste sector. | eSentire reported observing threat actors exploiting a flaw in Fortinet FortiClient EMS (CVE-2026-35616, CVSS score: 9.1) to deploy an information stealer called EKZ Stealer against a customer in the energy, utilities, and waste sector with the end goal of harvesting credentials from Chromium-based browsers and Firefox and exfiltrating them via PowerShell.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
EKZ Stealer's compiler-based obfuscations (indirect jumps/calls + control-flow flattening) are deobfuscated using Binary Ninja Workflows
we decoded the PowerShell command ... found that it downloads EKZ Infostealer, disguises it as a Fortinet update (FortiEndpoint_Patch.exe), and executes it.
del C:\programdata\log.txt;del C:\programdata\FortiEndpoint_Patch.exe;
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer used after exploitation of Fortinet FortiClient EMS to harvest browser credentials from Chromium-based browsers and Firefox and exfiltrate them via PowerShell.
An information stealer used to harvest credentials from Chromium-based browsers and Firefox and exfiltrate them via PowerShell after exploitation of Fortinet FortiClient EMS.
Credential-stealing malware delivered as a fake Fortinet patch (FortiEndpoint_Patch.exe). It harvests browser credentials from Chromium-based browsers and Firefox, writes them to log.txt, and the stolen data is then exfiltrated via a Base64-encoded HTTP POST request. The sample also uses compiler-based obfuscation including indirect jumps/calls, control-flow flattening, and XOR-based string encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.