Cyber Security News

BrazenBamboo APT Exploiting FortiClient Zero-Day to Steal User Credentials

A sophisticated cyber espionage campaign conducted by a threat actor known as BrazenBamboo. The group is exploiting an unpatched vulnerability in Fortinet’s FortiClient VPN software for Windows to steal user credentials, as part of a broader attack using a modular malware framework called DEEPDATA.

The zero-day vulnerability, discovered in July 2024, allows attackers to extract VPN credentials from the memory of FortiClient processes. This flaw affects even the latest version of FortiClient (v7.4.0) available at the time of discovery.

BrazenBamboo, believed to be a Chinese state-affiliated threat actor, has developed multiple malware families including DEEPDATA, DEEPPOST, and LIGHTSPY.

BrazenBamboo APT

The DEEPDATA framework consists of a loader (data.dll) and various plugins designed to gather sensitive information from compromised Windows systems.

Maximizing Cybersecurity ROI: Expert Tips for SME & MSP Leaders - Attend Free Webinar

The FortiClient exploit is implemented through a plugin named “msenvico.dll,” which extracts usernames, passwords, remote gateways, and ports from JSON objects in the VPN client’s memory.

This technique is reminiscent of a similar vulnerability discovered in 2016, though the current exploit affects newer versions of FortiClient.

DEEPDATA’s capabilities extend beyond credential theft, encompassing the collection of data from popular messaging apps, browsers, and email clients. The malware can also record audio, capture keystrokes, and exfiltrate files from infected systems.

Volexity’s analysis reveals that BrazenBamboo maintains a sophisticated infrastructure for command and control (C2) operations. The group uses multiple servers for hosting malware payloads and management applications, with evidence suggesting ongoing development of their tools.

The researchers assess with medium confidence that BrazenBamboo is likely a private enterprise producing capabilities for government operators focused on domestic targets. This assessment is based on the language used in C2 infrastructure, architectural decisions in malware development, and the continued operation despite public exposure.

Volexity reported the FortiClient vulnerability to Fortinet on July 18, 2024, and Fortinet acknowledged the issue on July 24, 2024. However, as of the time of Volexity’s report (November 2024), the issue remains unresolved and no CVE number has been assigned.

The discovery of this campaign highlights the persistent threat posed by well-resourced APT groups and the importance of prompt patching. Organizations using FortiClient VPN are advised to monitor for updates from Fortinet and implement additional security measures to protect sensitive credentials.

As the threat landscape continues to evolve, cybersecurity professionals must remain vigilant against sophisticated actors like BrazenBamboo, who demonstrate the ability to exploit zero-day vulnerabilities in widely-used security software.

Simplify and speed up Threat Analysis Workflow by Auto-detonating Cyber Attacks in a Malware sandbox

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago