🗾ITmedia AI+ (日本)•較早收集於 83m
LLM偵察106國2516個FortiGate目標

#cyberattack#reconnaissance#multi-countryclaude-codeclaude-codedeepseekfortigate
💡First reported LLM-automated cyberattack on firewalls—learn how attackers use Claude for recon
⚡ 30-Second TL;DR
有什麼變化
攻擊透過FortiGate漏洞影響106國2516目標
為什麼重要
凸顯LLM助長複雜網路攻擊風險,敦促AI從業者優先防範模型濫用。使用FortiGate的企業須加強AI輔助威脅監控。
下一步行動
Audit FortiGate logs for anomalous LLM-like query patterns immediately.
誰應關注:Enterprise & Security Teams
關鍵要點
- •攻擊透過FortiGate漏洞影響106國2516目標
- •Claude Code與DeepSeek用於自動化偵察與規劃
- •LLM整合入侵後多國同步攻擊
🧠 深度解析
背景與延伸:來自公開資料,非原文內容。引用 10 個來源。
🔑 增強重點摘要
- •The threat actor, likely Russian-speaking and financially motivated, originated scans from IP 212.11.64.250 and targeted management ports 443, 8443, 10443, and 4443 without exploiting vulnerabilities[1][3][4].
- •Post-exploitation involved Active Directory attacks like DCSync, pass-the-hash, pass-the-ticket, NTLM relay, and targeting backup systems such as Veeam using known CVEs like CVE-2024-40711[1][4].
- •Custom tools included ARXON MCP server for LLM processing, CHECKER2 Go-based orchestrator for VPN scanning, and prior use of HexStrike AI framework exposed in December 2025[2][3].
🛠️ 技術深入
- •Attackers used a custom Model Context Protocol (MCP) server named ARXON to process reconnaissance data, invoke DeepSeek for attack plans, and modify victim infrastructure[2][3].
- •CHECKER2, a Go-based orchestrator, enabled parallel VPN scanning and target processing[3].
- •Scripts like deepseek_attack_plan.py cataloged vulnerable systems, including ZKSoftware biometric devices potentially via CVE-2026-24061 telnet bypass[2].
- •Automated network classification by size, routing table analysis, Nuclei vulnerability scanning, SMB/DC identification, and HTTP service discovery[4].
🔮 前景展望AI analysis grounded in cited sources
AI will lower barriers for novice attackers to scale basic exploits globally
⏳ 時間線
2025-12
Server exposure reveals HexStrike AI framework and early FortiGate activity
2026-01
Mass scanning of FortiGate devices begins from IP 212.11.64.250
2026-01-11
Campaign start: Credential abuse on exposed management interfaces
2026-02-18
Active phase ends with 600+ compromises across 55 countries
2026-02-21
Cyber and Ramen discloses LLM use (Claude, DeepSeek) and custom tools
2026-02-25
Amazon Threat Intelligence and others report full campaign details
📎 來源 (10)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- zeron.one — AI Powered Fortigate Cyberattack 2026
- cyberandramen.net — Llms in the Kill Chain Inside a Custom Mcp Targeting Fortigate Devices Across Continents
- thehackernews.com — AI Assisted Threat Actor Compromises
- computing.co.uk — AI Powered Hacker Breaches 600 Fortigate Firewalls
- ampcuscyber.com — AI Powered Hacker Compromises 600 Fortigate Devices Worldwide
- cybersecuritynews.com — 600 Fortigate Devices Hacked
- sans.org — Xxviii 03
- evlconsulting.com.au — Cyber Incidents Digest 2026 02 22
- cyberpress.org — Deepseek Claude Target Fortigate
- mescomputing.com — AI Powered Ransomware Explodes in 2026 After a Brief 2025 Slowdown
📰
AI 週報
閱讀本週精選 AI 大事摘要 →
👉相關動態
AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: ITmedia AI+ (日本) ↗
每週 AI 簡報
每週一封,可隨時退訂。