AI-Augmented FortiGate Mass Exploitation — Russian-Speaking Actor Breaches 600+ Firewalls Across 55 Countries Using LLM-Generated Tooling and Custom MCP Framework
AI-Augmented FortiGate Mass Exploitation (TL-2026-0131), also tracked as AI-Augmented FortiGate Campaign, is a critical-severity advanced persistent threat campaign, first published 2026-02-22. It carries a reported Russia nexus and is not formally attributed, affects Fortinet FortiGate, references 3 CVEs (CVE-2019-7192, CVE-2023-27532, CVE-2024-40711), maps to 32 MITRE ATT&CK techniques (T1003.001, T1003.006, T1016), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-0131
- Threat ID
- TL-2026-0131
- Also known as
- AI-Augmented FortiGate Campaign, ARXON Campaign, CHECKER2 Campaign
- Severity
- CRITICAL
- Status
- MONITORING
- Category
- APT
- First published
- 2026-02-22
- Last reviewed
- 2026-02-22
- Attribution confidence
- NONE
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- government, telecommunications, manufacturing, media, healthcare, managed-service-providers, enterprise, critical-infrastructure
- Target regions
- South Asia, Latin America, Caribbean, West Africa, Northern Europe, Southeast Asia, Turkey, South Korea, Egypt, Vietnam, Kenya, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in AI-Augmented FortiGate Mass Exploitation
Malware and tooling: ARXON MCP Server, CHECKER2, HexStrike, gogo (port scanner)
Amazon Threat Intelligence disclosed a campaign by a Russian-speaking, financially motivated threat actor who breached 600+ FortiGate firewalls across 55+ countries between January 11 and February 18, 2026. The actor used brute-force attacks against exposed management interfaces (no zero-days) then leveraged multiple commercial LLM services (DeepSeek, Claude) to generate reconnaissance tools, automate credential extraction, plan lateral movement, and build a custom MCP server (ARXON) integrating AI directly into the kill chain. Post-access activity targeted SSL-VPN credentials, Active Directory via DCSync, and Veeam backup infrastructure — a classic pre-ransomware playbook. A misconfigured staging server (212.11.64.250) exposed 1,402 files providing unprecedented visibility into AI-assisted attack methodology.
How AI-Augmented FortiGate Mass Exploitation works
## Overview
On February 21, 2026, Amazon Integrated Security (CJ Moses, CISO) published research documenting a Russian-speaking threat actor who compromised 600+ FortiGate firewall appliances across 55+ countries in just 5 weeks (January 11 — February 18, 2026). The campaign was independently corroborated by Cyber and Ramen (Hunt.io research) and reported by BleepingComputer.
This campaign is significant not for sophisticated exploitation — no zero-days were used — but for demonstrating how commercial AI services enable low-to-medium skill actors to achieve nation-state-scale operations. The actor used at least two commercial LLM providers (DeepSeek and Anthropic Claude) throughout every phase of the kill chain: tool development, attack planning, reconnaissance automation, credential extraction, lateral movement planning, and operational documentation.
## Initial Access: Mass Credential Abuse
The actor's initial access was brute-force attacks against FortiGate management interfaces exposed to the internet. Systematic scanning targeted ports 443, 8443, 10443, and 4443, followed by authentication attempts using commonly reused credentials. No FortiGate vulnerabilities were exploited for initial access — the campaign succeeded entirely through exposed management ports and weak/single-factor credentials.
FortiGate configuration files were high-value targets containing: SSL-VPN user credentials with recoverable passwords, administrative credentials, complete network topology and routing information, firewall policies revealing internal architecture, and IPsec VPN peer configurations. The actor developed AI-assisted Python scripts to parse, decrypt, and organize stolen configurations.
## Geographic Distribution
The campaign's targeting was opportunistic rather than sector-specific, consistent with automated mass scanning. Concentrations of compromised devices were observed across South Asia, Latin America, the Caribbean, West Africa, Northern Europe, and Southeast Asia. Patterns of contiguous IP blocks and shared non-standard management ports indicated MSP deployments and large organizational networks.
Confirmed compromises included an industrial gas company in Asia-Pacific, a telecom provider in Turkey, and a major media company in Asia. Additional reconnaissance referenced targets in South Korea, Egypt, Vietnam, Kenya, and a medical equipment manufacturer.
## Custom Tooling: AI-Generated Reconnaissance Framework
### CHECKER2 (Go)
A Docker-based orchestrator for parallel VPN scanning and target processing. Logs showed processing of 2,516 targets across 106 countries in parallel batches. Each container follows the flow: ingest stolen VPN config → attempt connection → scan internal network → pass results to ARXON for LLM analysis.
### ARXON MCP Server (Python)
A custom Model Context Protocol (MCP) server — no public references found, likely purpose-built. ARXON serves dual roles: 1. **Analysis platform**: Ingests per-target recon data, calls DeepSeek to generate attack plans, stores results in a persistent knowledge base that grows with each target. 2. **Attack toolkit**: Contains scripts to directly modify victim infrastructure — batch SSH-based FortiGate VPN account creation, user provisioning, automated Domain Admin credential validation.
### AI-Generated Reconnaissance Tools (Go/Python)
Custom post-VPN reconnaissance tools with clear AI-generation indicators: redundant comments restating function names, simplistic architecture with disproportionate investment in formatting over functionality, naive JSON parsing via string matching rather than proper deserialization, compatibility shims for language built-ins with empty documentation stubs. The tools automate: ingesting target networks from VPN routing tables, classifying networks by size, running gogo port scanner for service discovery, identifying SMB hosts and domain controllers, and Nuclei vulnerability scanning against HTTP services.
## Post-Exploitation Methodology
### Domain Compromise Operational documentation (in Russian) detailed the use of Meterpreter with the mimikatz module to perform DCSync attacks against domain controllers, extracting NTLM password hashes from Active Directory. In confirmed compromises, the attacker obtained complete domain credential databases. In at least one case, the Domain Administrator used a plaintext password extracted from FortiGate configuration through password reuse.
### Lateral Movement Following domain compromise: pass-the-hash and pass-the-ticket attacks against additional infrastructure, NTLM relay attacks using standard poisoning tools (ntlmrelayx.py from Impacket), and remote command execution on Windows hosts.
### Backup Infrastructure Targeting The actor specifically targeted Veeam Backup & Replication servers using DecryptVeeamPasswords.ps1 (PowerShell credential extraction), compiled decryption tools, and exploitation attempts leveraging CVE-2023-27532 (Veeam information disclosure) and CVE-2024-40711 (Veeam RCE). This is a classic pre-ransomware indicator — destroying backup infrastructure before encryption.
### Limited Exploitation Success A critical finding: the actor largely failed when attempting to exploit anything beyond straightforward automated attack paths. Their own documentation records repeated failures against patched services, closed ports, and non-matching OS versions. When encountering hardened environments, they simply moved on to softer targets.
## AI as Force Multiplier
### Multi-Model Operational Workflow - **DeepSeek**: Used for generating structured attack plans from reconnaissance data, target triage, and tactical analysis. - **Claude/Claude Code**: Used for vulnerability assessments during live intrusions, tool development, attack planning, and was configured to autonomously execute offensive tools (Impacket, Metasploit, hashcat) without human approval per command. - At least two distinct commercial LLM providers used in complementary roles.
### AI-Generated Attack Planning AI generated comprehensive attack methodologies with step-by-step exploitation instructions, expected success rates, time estimates, and prioritized task trees. Plans referenced academic research on offensive AI agents. The AI produced technically accurate command sequences, but the actor struggled to adapt when conditions differed from the plan.
### Operational Evolution The operation evolved over 8+ weeks: - **December 2025**: Used HexStrike (open-source offensive MCP framework). Claude Code pre-approved to execute Impacket, Metasploit, hashcat with hardcoded victim credentials. - **February 2026**: Graduated to custom ARXON MCP server — fully automated exploitation system with persistent knowledge base.
## Staging Infrastructure
The misconfigured staging server at 212.11.64.250:9999 (AS4264, Global-Data System IT Corporation, Zurich, Switzerland) exposed 1,402 files across 139 subdirectories, including: - Stolen FortiGate configuration backups - Active Directory mapping data (BloodHound collection data) - Credential dumps and NTLM hashes - Vulnerability assessment reports (Claude Code-generated) - CVE exploit code - Nuclei scanning templates - Veeam credential extraction tools - claude-0/ and claude/ directories with 200+ files (task outputs, session diffs, cached prompt states) - ARXON MCP server source code - CHECKER2 orchestrator - deploy_output.log showing 102MB archive of FortiGate configs organized by country - Russian-language operational documentation
A second staging server at 185.196.11.225 (Kali Linux) was used for automated scanning, receiving the 102MB config archive and launching parallel processing.
## Threat Actor Assessment (Amazon)
- **Motivation**: Financially motivated (pre-ransomware TTPs) - **Language**: Russian-speaking (operational documentation in Russian) - **Skill Level**: Low-to-medium baseline, significantly augmented by AI - **AI Dependency**: Extensive — all operational phases - **Operational Scale**: 600+ devices, 55+ countries, 5 weeks - **Post-Exploitation Depth**: Shallow — fails against hardened targets, moves on - **Operational Security**: Inadequate — unencrypted staging server with victim data
## Remediation
### Immediate Actions - Audit all FortiGate management interface exposure — disable internet-facing management ports - Enable MFA on all FortiGate administrative and VPN accounts - Rotate all SSL-VPN and administrative credentials on FortiGate devices - Check for unauthorized VPN accounts created via SSH (ARXON capability) - Review FortiGate configuration backups for signs of extraction - Audit Active Directory for DCSync indicators and NTLM relay artifacts
### Long-Term Defenses - Network segmentation — isolate management interfaces from internet - Implement certificate-based VPN authentication - Deploy Veeam backup hardening (immutable backups, MFA) - Monitor for AI-generated tooling patterns in endpoint logs - Audit SSH sessions to FortiGate appliances for bulk modifications - Deploy detection for CHECKER2/ARXON tool artifacts
MITRE ATT&CK techniques used in TL-2026-0131
credential-access
T1003.001 LSASS Memory; T1003.006 DCSync; T1110.003 Password Spraying; T1552.001 Credentials In Files; T1557.001 Name Resolution Poisoning and SMB Relay; T1558 Steal or Forge Kerberos Tickets
discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1046 Network Service Discovery; T1069.002 Domain Groups; T1087.002 Domain Account
lateral-movement
T1021.002 SMB/Windows Admin Shares
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1059.001 PowerShell; T1059.004 Unix Shell; T1059.006 Python
defense-evasion
T1070 Indicator Removal; T1078 Valid Accounts; T1078.001 Default Accounts; T1078.002 Domain Accounts; T1550.002 Pass the Hash; T1550.003 Pass the Ticket
persistence
T1098 Account Manipulation; T1133 External Remote Services
command-and-control
T1105 Ingress Tool Transfer; T1219 Remote Access Tools
collection
T1213 Data from Information Repositories; T1602.002 Network Device Configuration Dump
impact
resource-development
Affected products and versions in AI-Augmented FortiGate Mass Exploitation
- Fortinet — FortiGate
Vulnerable versions: All versions with exposed management interfaces and weak credentials
Fixed in: N/A — configuration hardening required, not a software vulnerability - Veeam — Backup & Replication
Vulnerable versions: Versions vulnerable to CVE-2023-27532; Versions vulnerable to CVE-2024-40711
Fixed in: 12.1.2.172 and later (CVE-2024-40711); 12.0.0.1420 P20230718 and later (CVE-2023-27532) - QNAP — NAS
Vulnerable versions: Versions vulnerable to CVE-2019-7192
Fixed in: QTS 4.3.6.0923 and later - Microsoft — Active Directory
Vulnerable versions: All versions — targeted via DCSync with stolen credentials
Fixed in: N/A — credential-based attack
Remediation for AI-Augmented FortiGate Mass Exploitation
Patches
- Patch Veeam Backup & Replication for CVE-2023-27532 and CVE-2024-40711
- Patch QNAP NAS devices for CVE-2019-7192
- Update FortiGate firmware to latest stable release
- Enable FortiGate FGFM management plane hardening
Immediate actions
- Audit FortiGate management interface exposure — disable internet-facing management on ports 443, 8443, 10443, 4443
- Enable MFA on all FortiGate administrative and VPN accounts immediately
- Rotate all SSL-VPN and administrative credentials on FortiGate devices
- Check for unauthorized VPN user accounts created via SSH (ARXON batch provisioning)
- Review FortiGate configuration backups for signs of unauthorized extraction
- Audit Active Directory for DCSync indicators (Event ID 4662 with DS-Replication-Get-Changes)
- Check Veeam Backup servers for exploitation attempts (CVE-2023-27532, CVE-2024-40711)
- Block known staging IPs: 212.11.64.250, 185.196.11.225
Workarounds
- Restrict FortiGate management to internal/VPN-only access
- Disable recoverable password storage in FortiGate SSL-VPN config
- Enable SMB signing on all domain controllers and servers
- Implement geofencing on VPN access if organization has limited geographic footprint
Longer-term hardening
- Network segmentation — isolate management interfaces from internet access
- Implement certificate-based VPN authentication instead of password-only
- Deploy immutable backups and MFA on Veeam Backup infrastructure
- Monitor for AI-generated tooling patterns (redundant comments, naive parsing, formatting over functionality)
- Audit all SSH sessions to FortiGate appliances for bulk configuration changes
- Deploy EDR with behavioral detection for Impacket, Metasploit, mimikatz
- Implement NTLM relay protections (SMB signing, Extended Protection for Authentication)
- Regular credential audits — ensure VPN passwords differ from AD credentials
CVEs associated with AI-Augmented FortiGate Mass Exploitation
Weaknesses (CWE) in AI-Augmented FortiGate Mass Exploitation
CWE-521, CWE-306, CWE-522, CWE-798
Timeline of AI-Augmented FortiGate Mass Exploitation
- First exposure of staging server 212.11.64.250 detected by Hunt.io Attack Capture — contained HexStrike MCP framework, BloodHound data, Claude Code settings with hardcoded victim credentials from Asian media company. Source: https://cyberandramen.net/2026/02/21/llms-in-the-kill-chain-inside-a-custom-mcp-targeting-fortigate-devices-across-continents/
- Campaign begins — actor starts mass brute-force scanning of FortiGate management interfaces across ports 443, 8443, 10443, 4443. CHECKER2 Docker orchestrator deployed for parallel VPN scanning. Source: https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/
- Claude Code-generated vulnerability assessment report dated Feb 1, 2026 found on staging server, documenting active intrusion against Asia-Pacific industrial gas company — confirmed 400ms RTT to target. Impacket ntlmrelayx.py actively running. Source: Cyber and Ramen research
- Campaign activity window closes — 600+ FortiGate devices compromised across 55+ countries in 38 days. ARXON MCP evolved from HexStrike to fully automated exploitation system. Source: Amazon Threat Intelligence
- Amazon AWS Security Blog publishes research by CJ Moses (CISO). Cyber and Ramen publishes independent technical analysis of ARXON MCP and CHECKER2. BleepingComputer reports story. CronUp researcher German Fernandez identifies separate AI-generated FortiWeb tooling. Sources: AWS, Cyber and Ramen, BleepingComputer
- Threadlinqs Intelligence Platform publishes TL-2026-0131 with full MITRE mapping, detection coverage, and simulation documentation.
- As of 2026-05-29, the discrete 5-week campaign (Jan 11-Feb 18, 2026) has concluded, but the Russian-speaking actor remains unattributed with no arrest, takedown, or successor reported, and the AI-augmented TTPs plus exposed-FortiGate attack surface persist. The core vector is config-hardening, not a patchable CVE; secondary tool CVE-2024-40711 (Veeam) stays in CISA KEV under active ransomware exploitation, warranting continued monitoring rather than closure.
Sources cited for AI-Augmented FortiGate Mass Exploitation
- Amazon AWS Security Blog: AI-Augmented Threat Actor Accesses FortiGate Devices at Scale
- BleepingComputer: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks
- Cyber and Ramen: LLMs in the Kill Chain — Inside a Custom MCP Targeting FortiGate Devices Across Continents
- NVD — CVE-2023-27532: Veeam Information Disclosure
- NVD — CVE-2024-40711: Veeam RCE
- NVD — CVE-2019-7192: QNAP RCE
- VirusTotal: DecryptVeeamPasswords.ps1 from staging server
- Hunt.io: Attack Capture — Staging Server Analysis
- HexStrike: Open-source Offensive Security MCP Framework
- Google: Hackers Abusing Gemini AI for All Attack Stages
- Veeam KB4424: CVE-2023-27532 Advisory
- Veeam KB4649: CVE-2024-40711 Advisory
More in apt
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)
Detection coverage for TL-2026-0131
As of 2026-02-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0131 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.