216.73.216.226

AI-augmented threat actor accesses FortiGate devices at scale

· Published 21/04/2026 16:20 · Modified 22/04/2026 08:59

Export JSON

Essential information

Published
21/04/2026 16:20
Modified
22/04/2026 08:59
Tags
2026-04-21 CVE-2019-7192 CVE-2023-27532 CVE-2024-40711 active directory compromise ai-augmented attacks backup infrastructure targeting credential abuse dcsync fortigate meterpreter mimikatz russian-speaking actor vpn exploitation
Related entities
3 vulnerabilities (cve), 2 observables, 20 techniques (mitre), 2 malware

Description

A Russian-speaking financially motivated threat actor leveraged multiple commercial generative AI services to compromise over 600 devices across more than 55 countries between January and February 2026. The campaign exploited exposed management ports and weak credentials with single-factor authentication rather than software vulnerabilities. The actor used AI throughout all operational phases including tool development, attack planning, and reconnaissance automation, achieving scale previously requiring larger skilled teams. Post-exploitation activities included , credential harvesting, and targeting backup infrastructure consistent with pre-ransomware operations. Despite limited technical capabilities, the actor successfully extracted complete credential databases from multiple organizations, though they failed against hardened environments and moved to softer targets.

External references