FortiGate Hackers Leverage Critical FortiOS Vulnerability for PivotC2 Malware

by priyanka.patel tech editor
FortiGate Hackers Leverage Critical FortiOS Vulnerability for PivotC2 Malware

Hackers are exploiting a critical FortiGate vulnerability, CVE-2025-25249, to deploy a custom Node.js remote-access malware called PivotC2, according to SOCRadar’s Threat Research Unit. The attack leverages a heap-based buffer overflow in FortiOS and FortiSwitchManager, allowing unauthenticated remote code execution. Organizations are urged to patch immediately.

SOCRadar’s investigation reveals that threat actors are exploiting CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon of FortiOS and FortiSwitchManager, to compromise FortiGate appliances. The vulnerability, disclosed and patched by Fortinet in January 2026, enables unauthenticated remote code execution through specially crafted packets sent to the CAPWAP Control service on UDP port 5246. Attackers use this access to install PivotC2, a Node.js-based command-and-control framework designed to operate directly on compromised devices.

The Malware’s Unique Tactics

PivotC2 distinguishes itself from traditional malware by running on the compromised FortiGate appliance rather than on endpoint devices. This allows attackers to leverage the firewall’s privileged network position to monitor traffic, collect credentials, and establish persistence. The malware uses Node.js, which provides built-in networking capabilities and cross-platform compatibility, making it harder to detect as conventional native binaries. SOCRadar noted that the framework’s detailed inline comments and structured usage guidance suggest it was developed with AI-assisted coding tools.

The attack process involves automation scripts that repeatedly attempt exploitation until successful. Once the buffer overflow triggers, a reverse shell is opened, and a JavaScript stager fetches a second-stage payload from an attacker-controlled server. This payload, PivotC2, initiates outbound TLS connections to its command-and-control server, bypassing inbound firewall restrictions. It includes features like interactive shells, file transfers, and SOCKS5 proxy tunneling, along with FortiGate-specific functions to decrypt credentials and extract network configurations.

Scale and Geographical Impact

STRU researchers confirmed that attackers scanned over 30,000 FortiGate IP addresses, successfully compromising 178 devices. The United States had the highest concentration of infections, followed by Chile, Colombia, and the United Kingdom. Investigators identified two full network intrusions in the U.S., involving lateral movement, browser credential theft, and exfiltration of Microsoft Exchange mailbox data to Wasabi cloud storage. The campaign is attributed to a Russian-speaking, financially motivated cybercrime group, based on code comments, AI tooling, and exfiltration patterns.

The malware’s “auto-mode” feature automates the compromise of infected devices, harvesting configurations, decrypting credentials, and launching port scans without operator input. This enables large-scale, hands-off attacks. SOCRadar’s analysis of the malware’s version 0.2.3 indicates it is still in active development, with features like AES-256-CBC and AES-128-GCM decryption routines to extract sensitive data such as VPN pre-shared keys and wireless network passwords.

Response and Mitigation

Fortinet issued patches for affected versions of FortiOS and FortiSwitchManager in January 2026. Organizations are advised to upgrade to FortiOS 7.6.4, 7.4.9, 7.2.12, or 7.0.18 and above, or FortiSwitchManager 7.2.7 or 7.0.6 and above. Administrators should restrict external exposure to CAPWAP Control ports, hunt for suspicious Node.js processes, and check active sessions for connections to known malicious IP addresses. SOCRadar emphasized that updating systems is critical, but organizations must also consider whether devices may have been compromised before remediation.

FortiGate Hackers Leverage Critical FortiOS Vulnerability for PivotC2 Malware
Photo: Linkedin

The public Fortinet advisory did not confirm active exploitation of CVE-2025-25249 or reference PivotC2 by name as of publication. However, SOCRadar’s research, supported by STRU’s analysis, highlights the evolving nature of post-exploitation threats. The campaign underscores the risks of vulnerabilities that transition from patch-management concerns to complex, network-level attacks, requiring organizations to adopt proactive monitoring and threat-hunting strategies.

What This Means for Enterprises

The exploitation of CVE-2025-25249 demonstrates the growing sophistication of cybercriminals in targeting network infrastructure. By turning firewalls into attack platforms, attackers gain unprecedented access to internal networks, bypassing traditional endpoint security measures. The use of AI-assisted tooling and Node.js-based malware reflects broader trends in cybercrime, where attackers leverage modern technologies to evade detection and scale operations.

Hackers are exploiting a vulnerability in Fortinet Firewalls that allows unauthorized access.

For enterprises, the incident underscores the urgency of patch management and network segmentation. Even patched systems may require forensic analysis to determine if they were compromised before updates were applied. The attack also highlights the need for continuous monitoring of unexpected processes, such as Node.js activity on network appliances, and for organizations to stay informed about emerging threats tied to critical infrastructure components like FortiGate.

Hackers Retain Access to Patched FortiGate VPNs via Symlinks 🚨🔐 | Fortinet Warning

You may also like