ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Chinese FortiGate Espionage Campaign Snares 20,000+ Victims

criticalThreat actorimportance 60CVE-2022-42475

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-42475
Unauthenticated Heap Overflow in Fortinet FortiOS/FortiProxy SSL-VPN (Critical RCE)

CVE-2022-42475 is a critical (CVSS 9.8) heap-based buffer overflow in the SSL-VPN service of Fortinet FortiOS and FortiProxy. A remote, unauthenticated attacker can trigger it by sending specifically crafted requests to an exposed SSL-VPN interface, with no user interaction or credentials required. Successful exploitation yields arbitrary code or command execution on the appliance, giving attackers a foothold on the perimeter device from which they can pivot into internal networks. Any organization running the listed FortiOS (6.0 through 7.2) or FortiProxy (7.0/7.2) versions with SSL-VPN enabled is affected. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, has near-certain exploitation probability (EPSS 99.5%), and has been used in targeted government attacks and a Chinese-nexus espionage campaign that compromised over 20,000 systems, with attackers also noted to retain access even after patching.

Do: Upgrade FortiOS and FortiProxy to fixed releases per Fortinet advisory FG-IR-22-398 (any version beyond the listed affected ranges), and reboot the appliance after patching to clear lingering SSL-VPN sessions since attackers have been observed retaining access post-patch. Check for indicators of compromise such as unknown local accounts, unexpected processes, and anomalous historical logins, and rotate SSL-VPN credentials if compromise is suspected. If SSL-VPN is not required, disable it or restrict exposure to trusted sources until patched.

9.899% KEV ransomware PoC
  • Fortinet FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, and 6.0.15 and earlier
  • Fortinet FortiProxy SSL-VPN 7.2.0 through 7.2.1, and 7.0.7 and earlier
masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL-VPN endpoints (well over 100,000; 20,000+ confirmed victims in a single campaign)
Full article322 words · extracted from infosecurity-magazine.com · click to collapse

A sophisticated Chinese espionage campaign targeting Fortinet edge devices was far more extensive than previously thought, resulting in the compromise of at least 20,000 systems worldwide, according to the Dutch authorities.

The country’s intelligence services first revealed the campaign in February this year. They said Chinese spies exploited a zero-day vulnerability (CVE-2022-42475) in FortiGate appliances to deploy the Coathanger remote access Trojan (RAT) on Dutch defense networks.

However, the Dutch National Cyber Security Centre (NCSC) said in a new post this week that during the two months before Fortinet released a patch for the zero-day bug, the threat actors managed to compromise at least 14,000 targets. These included “dozens of (Western) governments, international organizations and a large number of companies within the defense industry,” it said.

The total number of infections within a few months in 2022 and 2023 is thought to be at least 20,000, with a “significant number” likely to still be impacted due to the difficulty of identifying and removing the RAT malware.

“The state actor installed malware at relevant targets at a later time. This gave the state actor permanent access to the systems. Even if a victim installs security updates from FortiGate, the state actor continues to have this access,” the update read.

“It is not known how many victims actually have malware installed. The Dutch intelligence services and the NCSC consider it likely that the state actor could potentially expand its access to hundreds of victims worldwide and carry out additional actions such as stealing data.”

Read more on Chinese espionage campaign: Chinese Cyber-Espionage Groups Increasingly Targeting Russia

The campaign has echoes of other espionage efforts by the Chinese state targeting cybersecurity appliances in a persistent manner.

Barracuda was forced to tell customers to replace their ESG appliances last year after Beijing-backed group UNC4841 targeted them. Also last year, unpatched SonicWall Secure Mobile Access (SMA) appliances were targeted by UNC4540.

Image credit: JHVEPhoto / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/chinese-fortigate-espionage-20000/