Cyber Threat Report: 'Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation'

Report Author Mandiant
Publication Date 2023-03-16
Original Reporting Source
Attributed to Nation China
Related Intrusion Sets UNC3886
Identified CVEs CVE-2022-41328

This blog post by threat researchers at Mandiant outlines intrusions activity by the UNC3886 intrusion set which involved the deployment of backdoors to Fortinet and VMWare platforms. The actor used a directory traversal zero-day (CVE-2022-41328) to deploy capabilities to FortiGate firewall devices. The actor was then able to redirect traffic on the devices and gain persistence on FortiManager and FortiAnalyzer devices. The group has also been observed deploying a VMWare ESXi hypervisor malware framework and Mandiant analysts observed connections between compromised Fortinet devices and 'VIRTUALPITA' backdoors on VMWare systems. Mandiant attribute UNC3886 as an advanced espionage group with a suspected China nexus.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques