AI-augmented threat actor accesses FortiGate devices at scale
Essential information
- Published
- 21/04/2026 16:20
- Modified
- 22/04/2026 08:59
- Tags
- 2026-04-21 CVE-2019-7192 CVE-2023-27532 CVE-2024-40711 active directory compromise ai-augmented attacks backup infrastructure targeting credential abuse dcsync fortigate meterpreter mimikatz russian-speaking actor vpn exploitation
- Related entities
- 3 vulnerabilities (cve), 2 observables, 20 techniques (mitre), 2 malware
Description
A Russian-speaking financially motivated threat actor leveraged multiple commercial generative AI services to compromise over 600 FortiGate devices across more than 55 countries between January and February 2026. The campaign exploited exposed management ports and weak credentials with single-factor authentication rather than software vulnerabilities. The actor used AI throughout all operational phases including tool development, attack planning, and reconnaissance automation, achieving scale previously requiring larger skilled teams. Post-exploitation activities included Active Directory compromise, credential harvesting, and targeting backup infrastructure consistent with pre-ransomware operations. Despite limited technical capabilities, the actor successfully extracted complete credential databases from multiple organizations, though they failed against hardened environments and moved to softer targets.