The provided items do not describe a single cohesive incident; they are a mix of unrelated security research, tooling write-ups, newsletters, and commentary. The most concrete incident reporting is an AI-assisted intrusion campaign in which a Russian-speaking financially motivated actor compromised 600+ Fortinet FortiGate devices by targeting internet-exposed management interfaces with weak credentials and no MFA, then using AI-generated scripts for recon, configuration theft, and follow-on activity (including attempts to move laterally into Active Directory, extract database credentials, and access backup infrastructure). Separately, Kaspersky-linked reporting described Arkanix Stealer as a short-lived infostealer operation marketed in late 2025 with a modular design and anti-analysis features, with indicators of LLM-assisted development and a brief operational lifespan after promotion on dark-web forums and use of Discord for “customer” support.
Other references are not about that Fortinet campaign and instead cover distinct topics: academic research demonstrating 27 attacks against major password managers under a malicious server model (undermining “zero-knowledge” assumptions via missing ciphertext integrity/binding), GreyNoise telemetry on OAST/interactsh callback-domain scanning trends, and a vendor-style overview of an AI-driven pentesting framework (PentAGI) integrating 20+ tools. Several entries are primarily roundup/newsletter content or generic guidance/commentary (e.g., phishing what-to-do advice, compliance vs. security, historical/legal computing anecdote), and one is a threat-actor profile tying Lotus Blossom to a separate Notepad++ update-channel incident rather than the Fortinet activity.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
AWS assessed that a Russian-speaking financially motivated threat actor compromised over 600 FortiGate firewalls at scale. Post-compromise activity included lateral movement, Active Directory compromise, credential extraction, and attempts to access backup infrastructure, suggesting possible initial-access-broker activity.
Kaspersky publicly documented Arkanix Stealer, describing coding artifacts consistent with LLM-assisted development and detailing features such as anti-analysis, wallet injection, and the ChromElevator post-exploitation tool. The report also released indicators of compromise including file hashes, domains, and IP addresses tied to Arkanix detections.
Logs from the attackers' misconfigured infrastructure showed automated processing of more than 2,500 devices across 106 countries using custom tools including CHECKER2 and ARXON. The system integrated DeepSeek and Claude to generate attack plans, run tooling, and prioritize post-compromise actions.
In early February 2026, researchers identified an active campaign targeting exposed Fortinet FortiGate devices using weak passwords and no MFA rather than zero-days. The operation used AI-generated scripts and an automated workflow to steal configurations, gain access, and conduct follow-on intrusion activity.
Roughly two months after launch, the Arkanix author took down the malware's control panel and Discord server without notice, ending the short-lived operation and making tracking more difficult. Kaspersky later assessed the project as likely an AI/LLM-assisted experiment.
In late 2025, the Arkanix Stealer malware operation was advertised across multiple dark web forums as a modular information stealer sold in basic Python and premium native C++ tiers. The operator also ran a control panel, Discord server, and referral program to support customers and drive adoption.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
news.risky.biz
Open sourcecybersecuritynews.com
Open sourcenews.risky.biz
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.