UNC5820 is an unknown threat actor exploiting CVE-2024-47575 in Fortinet FortiManager to steal configurations and credentials.
Analyst brief
UNC5820 is an unknown threat actor exploiting CVE-2024-47575 (FortiJump), a critical vulnerability in Fortinet FortiManager, to bypass authentication and execute arbitrary commands. The actor primarily targets managed FortiGate devices to collect configuration data, user information, and FortiOS256-hashed passwords through data staging and exfiltration. Key TTPs involve crafting specific requests for authentication bypass, arbitrary command execution for reconnaissance, and exfiltration of sensitive configuration archives without observed lateral movement or malware deployment. Defenders should immediately patch FortiManager instances, closely monitor configuration change logs for unauthorized device registrations or modifications, and consider resetting potentially compromised credentials.
UNC5820
unknown
UNC5820 is a threat actor exploiting the CVE-2024-47575 vulnerability in Fortinet's FortiManager, allowing them to bypass authentication and execute arbitrary commands. They have been observed exfiltrating configuration data, user information, and FortiOS256-hashed passwords from managed FortiGate devices. While the actor has staged and exfiltrated sensitive data, there is currently no evidence of lateral movement or further compromise of additional environments. Mandiant has not determined whether UNC5820 is state-sponsored or identified its geographic location.