Cyber Security News

Hackers Leverage DeepSeek and Claude to Attack FortiGate Devices Worldwide

In early February 2026, a significant cybersecurity threat emerged involving the sophisticated use of Large Language Models (LLMs) in active intrusion campaigns.

A misconfigured server exposed a detailed software pipeline where threat actors integrated DeepSeek and Claude into their attack workflows.

This discovery highlights a dangerous evolution in modern cybercrime, where AI tools are not just generating text but are embedded into the kill chain to automate complex offensive tasks against global targets.

The attack infrastructure specifically targeted FortiGate SSL VPN appliances, utilizing stolen configuration data to breach networks effectively.

By leveraging these compromised credentials, the operators successfully mapped internal infrastructures and identified critical assets.

The operation utilized custom-built tools to orchestrate these attacks, allowing for the simultaneous processing of thousands of targets without requiring manual intervention for every step of the intrusion process.

Evidence indicates that over 2,500 devices across 106 countries were processed in parallel batches.

Cyber and Ramen analysts identified that the threat actors utilized a dual-model approach, using DeepSeek to generate strategic attack plans based on reconnaissance data while employing Claude’s coding capabilities to execute vulnerability assessments.

This level of automation enabled even low-skilled operators to manage a massive volume of intrusions efficiently.

Automated Exploitation Workflow

The core of this operation relies on two custom components named ARXON and CHECKER2. CHECKER2 functions as a Docker-based orchestrator that handles parallel VPN scanning, while ARXON acts as a Model Context Protocol (MCP) server.

This bridge allows the attackers to feed specific network data into the LLMs, which then output actionable exploitation steps. For instance, the intrusion chain diagram illustrates how the system moves from initial access to active exploitation.

Intrusion chain (Source – Cyber and Ramen)

Once inside a network, the system uses Claude to run offensive tools like Impacket and Metasploit autonomously. 

While the redacted snippet of the vulnerability assessment report found on the server displays how the model documents its findings and suggests prioritized next steps, such as escalating privileges.

Redacted snippet of the vulnerability assessment report found on the server (Source – Cyber and Ramen)

The exposed logs confirm that this automated system is actively targeting diverse sectors, including telecommunications.

Snippet of the contents of deploy_output.log showing thousands of targets across the world (Source – Cyber and Ramen)

To mitigate these AI-driven threats, organizations must prioritize patching edge devices immediately, as the speed of automated attacks leaves little room for delay.

Security teams should regularly audit VPN user accounts for unauthorized creations and monitor for unexpected SSH sessions. Additionally, verifying network configurations against known baselines can help detect the subtle modifications typical of this campaign.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago