A confirmed Conti ransomware intrusion began with an outdated FortiGate firewall, giving attackers initial access before they escalated privileges to domain administrator, moved laterally, and staged ransomware across nearly 300 systems. Investigators linked the entry point to likely exploited FortiGate vulnerabilities including CVE-2018-13379 and CVE-2018-13374, after which the attackers deployed Cobalt Strike beacons, used WMI for remote execution, and relied on batch scripts and reflective DLL injection to prepare the malware rollout.
The attackers also exfiltrated sensitive departmental data to MEGA using RClone before attempting to launch Conti broadly across the environment. Sophos said protected endpoints blocked the ransomware while unprotected devices were affected, and its Rapid Response team contained the incident and helped restore most critical infrastructure within 24 hours of engagement. The case illustrates how unpatched perimeter appliances can enable full-domain compromise, data theft, and large-scale ransomware deployment.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
The post-incident investigation identified a possible second data exfiltration, a second compromised account, and suspicious RDP traffic through the vulnerable firewall. Sophos also confirmed the outdated FortiGate device was the likely initial intrusion point.
By day 5, less than 24 hours after Sophos Rapid Response was engaged, the customer had restarted most critical infrastructure. The victim then recovered unprotected machines from backups or by re-imaging, deployed Sophos protections, and enabled multi-factor authentication on the VPN.
After ransomware deployment began, the victim blocked all internet traffic except Sophos traffic, shut down critical infrastructure, and engaged Sophos Rapid Response. Within the first 45 minutes, responders identified the compromised account, blocked the malicious DLL and C2 addresses, identified targeted endpoints, deployed Sophos Managed Threat Response, and began collecting forensic evidence; within the next 45 minutes they also built a list of exfiltrated data.
About 40 minutes after deployment, the Cobalt Strike beacons activated and used reflective DLL injection to fetch and execute the Conti ransomware payload directly in memory from command-and-control infrastructure. Sophos Intercept X blocked Conti on protected computers over the next three hours, but unprotected devices were damaged.
At about 1:00 a.m. local time on day 4, the attackers used batch scripts and prepared host lists to copy Cobalt Strike loaders to nearly 300 endpoints and servers. They tested execution on one server first, then used WMI and rundll32.exe to launch the loaders across server and workstation targets.
On day 3, the attackers spent about 10 hours identifying and exfiltrating potentially valuable data. They deployed RClone on the third server with MEGA credentials and stole data from Human Resources, IT, credit, accounting, senior staff, and budget-related directories, while also running a batch script to search for credential-related XLSX files.
On the first day of the intrusion, the attackers deployed Cobalt Strike, ran reconnaissance commands, and mapped the victim network. After the victim detected and shut down one compromised server, the attackers pivoted to a second server and resumed the intrusion, then used a compromised domain admin account and WMI to deploy another beacon to a third server.
An unnamed organization was compromised through a FortiGate firewall running vulnerable firmware version 5.6.3 build 1547(GA). Sophos later confirmed the outdated firewall was the initial access vector, with the attackers gaining domain admin access to two servers within 16 minutes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.