FBI and CISA warned that APT actors were actively scanning internet-facing Fortinet devices and exploiting multiple FortiOS vulnerabilities, including CVE-2018-13379, CVE-2020-12812, and CVE-2019-5591, to gain initial access and maintain a foothold for follow-on attacks. The agencies said the activity affected government, commercial, technology, and critical infrastructure organizations, with scanning observed on ports 4443, 8443, and 10443. In one cited case, an APT group almost certainly exploited a FortiGate appliance to access a web server hosting a U.S. municipal government domain and likely created the username elie on the network.
The campaign built on long-running exploitation of Fortinet SSL VPN weaknesses, especially the path traversal flaw CVE-2018-13379, which had already enabled the leak of credential-bearing session files from nearly 50,000 vulnerable devices worldwide. Those exposed sslvpn_websession files contained plaintext usernames and passwords, allowing attackers to reuse credentials even after patching. U.S. authorities said compromised access could support data exfiltration, ransomware-style encryption, and other post-exploitation activity, and highlighted indicators including FRP tunneling tools, unusual FTP traffic over port 443, and a scheduled task named SynchronizeTimeZone.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On May 27, 2021, the FBI, coordinated with CISA, issued Alert MI-000148-MW on APT exploitation of Fortinet FortiOS vulnerabilities. The notice added indicators of compromise and post-exploitation details including suspicious accounts, FRP binaries, Mimikatz, MinerGate, WinPEAS, SharpWMI, FTP over port 443, and a scheduled task named "SynchronizeTimeZone."
As of at least May 2021, the FBI assessed that an APT group almost certainly exploited a FortiGate appliance to access a webserver hosting the domain of a U.S. municipal government. The actors likely created the username "elie" on the network to support further malicious activity.
On April 2, 2021, FBI and CISA published Joint Cybersecurity Advisory AA21-092A warning that APT actors were exploiting multiple Fortinet FortiOS vulnerabilities to gain initial access. The agencies said the activity likely targeted government, commercial, technology services, and critical infrastructure networks for follow-on attacks such as data exfiltration or encryption.
In March 2021, FBI and CISA observed APT actors scanning internet-facing devices on ports 4443, 8443, and 10443 for systems vulnerable to CVE-2018-13379. They also observed enumeration related to CVE-2020-12812 and CVE-2019-5591.
Fortinet published an additional customer warning recommending upgrades for CVE-2018-13379. The warning is referenced as occurring in July 2020.
Fortinet published a customer warning about the FortiOS SSL vulnerability and recommended upgrades. The article identifies this as one of several follow-up warnings after the PSIRT advisory.
Fortinet issued a PSIRT advisory for the FortiOS SSL VPN path traversal vulnerability CVE-2018-13379. This is cited as the vendor's initial warning to customers about the flaw.
A threat actor leaked sslvpn_websession files from almost 50,000 vulnerable Fortinet VPN devices, exposing plaintext usernames, passwords, access levels, and users' original IP addresses. The leak created risks of credential stuffing and renewed access to patched devices using still-valid credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcefortinet.com
Open sourceic3.gov
Open sourceic3.gov
Open sourcefortiguard.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.