Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Russian-speaking threat actors are actively exploiting CVE-2025-25249, an unauthenticated RCE vulnerability in FortiOS and FortiSwitchManager, to deploy PivotC2. The Node.js RAT is purpose-built for the FortiGate architecture. The campaign targeted over 30,000 IP addresses. SOCRadar STRU confirmed 178 infected devices, with the highest concentration in the United States. At least two full intrusions resulted in data exfiltration.
On September 9, 2026, CISA added CVE-2025-25249 to the Known Exploited Vulnerabilities catalog. Binding Operational Directive 26-04 mandates forensic triage and patching within three days for federal agencies.
- 178 FortiGate devices confirmed infected with PivotC2 out of over 30,000 targeted IPs
- Native FortiGate RAT with automatic AES credential decryption and configuration harvesting
- CVE-2025-25249: CVSS 9.8 (Critical, NVD) vs. 7.4 (High, Fortinet)
- CISA BOD 26-04: mandatory forensic triage beyond patching for federal agencies
The CAPWAP Daemon Vulnerability and Scoring Discrepancy
CVE-2025-25249 is a heap-based buffer overflow in the cw_acd daemon of FortiOS and FortiSwitchManager. The service handles the CAPWAP protocol on UDP port 5246. The flaw allows unauthenticated RCE via specially crafted requests.
The National Vulnerability Database assigns CVSS v3 9.8 (Critical). Fortinet assigns 7.4 (High). Both assessments are documented without mutual revision. Patches were released in January 2026: FortiOS 7.6.4, 7.4.9, 7.2.12, 7.0.18; FortiSwitchManager 7.2.7, 7.0.6. Affected versions include all 6.4 releases and 7.x series prior to the patched versions.
PivotC2: Architecture and Documented Capabilities
PivotC2 is a post-exploitation framework built with specific knowledge of the FortiGate architecture. According to SOCRadar STRU's original analysis, the RAT performs automatic AES decryption of credentials, parsing of proprietary configuration files, and management of the VDOM structure.
The exploit binary fortirun.bin leverages CAPWAP discovery responses to bypass ASLR. A JavaScript stager downloads the RAT via HTTPS with XOR decryption using the hardcoded key pivot. The payload establishes an outbound TLS connection to the C2 server, using a custom binary framing protocol with a channel multiplexer: 13 documented message types, ranging from 0x01 to 0x0D.
The recovered version is 0.2.3, indicating an early development stage. The --auto mode executes configuration harvesting, credential extraction, and subnet scanning without operator intervention. Target files include global configurations, VDOM archives, and fsv_sync.dat. Exposed decrypted data comprises administrative credentials, SSL-VPN accounts, LDAP bind credentials, wireless pre-shared keys, and IPsec VPN secrets.
"Based on the observed inline comments and usage guidance, the actors highly likely leveraged AI to develop the RAT"
Campaign Metrics and Attribution
The campaign targeted over 30,000 IP addresses. SOCRadar STRU confirmed 178 PivotC2 sessions. The highest geographic concentration is in the United States. Two full intrusions resulted in confirmed data exfiltration, with TTPs including Active Directory enumeration, browser credential theft, reverse SSH relay, RDP configuration changes, and exfiltration via S3 buckets.
SOCRadar STRU assesses with high confidence attribution to Russian-speaking cybercrime, based on financially motivated tradecraft and Russian-language comments in files. No identification as a known APT emerges. The dossier does not specify the volume of exfiltrated data nor the victim entities.
The indication of AI-assisted development is based on heuristic analysis of inline comments; it is not confirmed by independent sources. SOCRadar STRU states it as "highly likely," not as certain.
Immediate Actions
- Apply patches to the correct versions: FortiOS 7.6.4, 7.4.9, 7.2.12, 7.0.18 or FortiSwitchManager 7.2.7, 7.0.6
- Conduct forensic triage on internet-exposed devices on UDP port 5246, verifying suspicious activity from July 2026 onward, as mandated by CISA BOD 26-04
- Inspect FortiGate configurations to detect unauthorized modifications, including verification of undocumented admin, VPN, and wireless accounts
Editorial Take: The Significance of Vendor-Specific Specialization
The nature of PivotC2 as a RAT built for a single platform signals an operational evolution. Traditional generic post-exploitation frameworks require manual adaptation to the target. PivotC2 incorporates native knowledge of FortiGate's cryptographic formats and configuration structures, reducing the time between initial compromise and access to usable credentials.
This specialization does not automatically turn proprietary complexity into a broader attack surface. The dossier does not document that vendor knowledge is the determining factor for scalability. The 30,000 targeted IPs and 178 confirmed infections reflect SOCRadar visibility, not necessarily the campaign's complete total.
CISA mandated forensic triage with BOD 26-04, recognizing that patching fixes the vulnerability but does not detect compromises that occurred before the update. This measure reflects the post-exploitation nature of the RAT, not a CISA assessment of patching insufficiency in general.
The indication of probable AI assistance in development, while not independently confirmed, introduces a cautionary variable. If confirmed, it would lower the technical skill barrier for building vendor-specific malware. At present, the dossier does not support conclusions on the future scalability of this model.
Source Limitations: Campaign analysis relies primarily on SOCRadar STRU findings, corroborated by CISA and NVD contextual confirmations. No independent primary sources on PivotC2 infrastructure exist at this time. SecurityWeek, CloudLinkTech, News4Hackers, and CyberPress report SOCRadar findings without additional original analysis.
Information has been verified against cited sources and is current as of publication.
Sources
- https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
- https://www.securityweek.com/fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/cve-2025-25249
- https://www.cloudlinktech.com/news/fortinet-rce-pivotc2-rat-cve-2025-25249/
- https://www.news4hackers.com/fortinet-code-execution-vulnerability-exploited-by-attackers-in-pivotc2-rat-campaigns
- https://cyberpress.org/critical-fortigate-flaw-exploited/
- https://podcast.securityweek.com/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.