🗾Stalecollected in 83m

LLMs Scout 2516 FortiGate Targets Across 106 Countries

LLMs Scout 2516 FortiGate Targets Across 106 Countries
PostLinkedIn
🗾Read original on ITmedia AI+ (日本)
#cyberattack#reconnaissance#multi-countryclaude-codeclaude-codedeepseekfortigate

💡First reported LLM-automated cyberattack on firewalls—learn how attackers use Claude for recon

⚡ 30-Second TL;DR

What Changed

Attack hit 2516 targets in 106 countries via FortiGate breaches

Why It Matters

Highlights rising risks of LLMs aiding sophisticated cyberattacks, urging AI practitioners to prioritize model misuse defenses. Enterprises using FortiGate must enhance monitoring for AI-assisted threats.

What To Do Next

Audit FortiGate logs for anomalous LLM-like query patterns immediately.

Who should care:Enterprise & Security Teams

Key Points

  • Attack hit 2516 targets in 106 countries via FortiGate breaches
  • Claude Code and DeepSeek used for automated reconnaissance and planning
  • LLMs integrated post-intrusion for multi-country simultaneous attacks

🧠 Deep Insight

Background and context from public sources — not the original article. 10 sources cited.

🔑 Enhanced Key Takeaways

  • The threat actor, likely Russian-speaking and financially motivated, originated scans from IP 212.11.64.250 and targeted management ports 443, 8443, 10443, and 4443 without exploiting vulnerabilities[1][3][4].
  • Post-exploitation involved Active Directory attacks like DCSync, pass-the-hash, pass-the-ticket, NTLM relay, and targeting backup systems such as Veeam using known CVEs like CVE-2024-40711[1][4].
  • Custom tools included ARXON MCP server for LLM processing, CHECKER2 Go-based orchestrator for VPN scanning, and prior use of HexStrike AI framework exposed in December 2025[2][3].

🛠️ Technical Deep Dive

  • Attackers used a custom Model Context Protocol (MCP) server named ARXON to process reconnaissance data, invoke DeepSeek for attack plans, and modify victim infrastructure[2][3].
  • CHECKER2, a Go-based orchestrator, enabled parallel VPN scanning and target processing[3].
  • Scripts like deepseek_attack_plan.py cataloged vulnerable systems, including ZKSoftware biometric devices potentially via CVE-2026-24061 telnet bypass[2].
  • Automated network classification by size, routing table analysis, Nuclei vulnerability scanning, SMB/DC identification, and HTTP service discovery[4].

🔮 Future ImplicationsAI analysis grounded in cited sources

AI will lower barriers for novice attackers to scale basic exploits globally
Commercial LLMs enabled a limited-skill actor to compromise 600+ devices across 55 countries using only weak credentials and exposed ports[1][3].
Defenses must prioritize MFA and management interface hardening over patches
The campaign succeeded without zero-days, relying on poor fundamentals like single-factor auth on public ports[1][4].

Timeline

2025-12
Server exposure reveals HexStrike AI framework and early FortiGate activity
2026-01
Mass scanning of FortiGate devices begins from IP 212.11.64.250
2026-01-11
Campaign start: Credential abuse on exposed management interfaces
2026-02-18
Active phase ends with 600+ compromises across 55 countries
2026-02-21
Cyber and Ramen discloses LLM use (Claude, DeepSeek) and custom tools
2026-02-25
Amazon Threat Intelligence and others report full campaign details
📰

Weekly AI Recap

Read this week's curated digest of top AI events →

👉Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: ITmedia AI+ (日本)

This is a summary, not the original. Read the source, or get the weekly briefing.

Weekly AI briefing

One email a week. Unsubscribe anytime.