08-09-2026
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
Report completeness: High
Actors/Campaigns:
Fortibleed
Lynx_ransomware
Threats:
Pivotc2
Portscan_tool
Credential_harvesting_technique
Proxychains_tool
Ldapdomaindump_tool
Obfs4proxy_tool
Passthehash_technique
Process_injection_technique
Victims:
Fortigate appliances, Us based organizations
Geo:
United kingdom, United states, Chile, Russian, Colombia
CVEs:
CVE-2025-25249 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: Unknown
Soft:
- fortinet fortios (<6.4.17, <7.0.18, <7.2.12, <7.4.9, <7.6.4)
CVE-2024-26304 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: Unknown
CVE-2024-47575 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- fortinet fortimanager (<6.2.13, <6.4.15, <7.0.13, <7.2.8, <7.4.5)
- fortinet fortimanager_cloud (le6.4.7, <7.0.13, <7.2.8, <7.4.5)
CVE-2026-35273 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- oracle peoplesoft_enterprise_peopletools (8.61, 8.62)
TTPs:
Tactics: 8
Technics: 26
IOCs:
Url: 1
File: 10
IP: 7
Hash: 12
Soft:
FortiGate, Node.js, busybox, Active Directory, SoftPerfect Network Scanner, Google Chrome, Chrome, Microsoft Edge, Microsoft Exchange, Linux, have more...
Wallets:
wassabi
Algorithms:
aes-256-cbc, aes-128-gcm, base64, cbc, xor, sha256, aes
Win API:
VirtualAllocEx, WriteProcessMemory, OpenProcess
Languages:
python, javascript, powershell, rust, cpython
Platforms:
arm
Links:
https://github.com/DhavalKapil/heap-exploitation/blob/master/attacks/house\_of\_einherjar.md