🗾較早收集於 83m

LLM偵察106國2516個FortiGate目標

LLM偵察106國2516個FortiGate目標
PostLinkedIn
🗾閱讀原文: ITmedia AI+ (日本)
#cyberattack#reconnaissance#multi-countryclaude-codeclaude-codedeepseekfortigate

💡First reported LLM-automated cyberattack on firewalls—learn how attackers use Claude for recon

⚡ 30-Second TL;DR

有什麼變化

攻擊透過FortiGate漏洞影響106國2516目標

為什麼重要

凸顯LLM助長複雜網路攻擊風險,敦促AI從業者優先防範模型濫用。使用FortiGate的企業須加強AI輔助威脅監控。

下一步行動

Audit FortiGate logs for anomalous LLM-like query patterns immediately.

誰應關注:Enterprise & Security Teams

關鍵要點

  • 攻擊透過FortiGate漏洞影響106國2516目標
  • Claude Code與DeepSeek用於自動化偵察與規劃
  • LLM整合入侵後多國同步攻擊

🧠 深度解析

背景與延伸:來自公開資料,非原文內容。引用 10 個來源。

🔑 增強重點摘要

  • The threat actor, likely Russian-speaking and financially motivated, originated scans from IP 212.11.64.250 and targeted management ports 443, 8443, 10443, and 4443 without exploiting vulnerabilities[1][3][4].
  • Post-exploitation involved Active Directory attacks like DCSync, pass-the-hash, pass-the-ticket, NTLM relay, and targeting backup systems such as Veeam using known CVEs like CVE-2024-40711[1][4].
  • Custom tools included ARXON MCP server for LLM processing, CHECKER2 Go-based orchestrator for VPN scanning, and prior use of HexStrike AI framework exposed in December 2025[2][3].

🛠️ 技術深入

  • Attackers used a custom Model Context Protocol (MCP) server named ARXON to process reconnaissance data, invoke DeepSeek for attack plans, and modify victim infrastructure[2][3].
  • CHECKER2, a Go-based orchestrator, enabled parallel VPN scanning and target processing[3].
  • Scripts like deepseek_attack_plan.py cataloged vulnerable systems, including ZKSoftware biometric devices potentially via CVE-2026-24061 telnet bypass[2].
  • Automated network classification by size, routing table analysis, Nuclei vulnerability scanning, SMB/DC identification, and HTTP service discovery[4].

🔮 前景展望AI analysis grounded in cited sources

AI will lower barriers for novice attackers to scale basic exploits globally
Commercial LLMs enabled a limited-skill actor to compromise 600+ devices across 55 countries using only weak credentials and exposed ports[1][3].
Defenses must prioritize MFA and management interface hardening over patches
The campaign succeeded without zero-days, relying on poor fundamentals like single-factor auth on public ports[1][4].

時間線

2025-12
Server exposure reveals HexStrike AI framework and early FortiGate activity
2026-01
Mass scanning of FortiGate devices begins from IP 212.11.64.250
2026-01-11
Campaign start: Credential abuse on exposed management interfaces
2026-02-18
Active phase ends with 600+ compromises across 55 countries
2026-02-21
Cyber and Ramen discloses LLM use (Claude, DeepSeek) and custom tools
2026-02-25
Amazon Threat Intelligence and others report full campaign details
📰

AI 週報

閱讀本週精選 AI 大事摘要 →

👉相關動態

AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: ITmedia AI+ (日本)

這是摘要,不是原文。去看原站,或訂閱每週簡報。

每週 AI 簡報

每週一封,可隨時退訂。