Full Report
A zero-day vulnerability in Fortinet's Windows VPN client, FortiClient, was discovered by Volexity, allowing user credentials to remain in process memory after authentication. This vulnerability was exploited by BrazenBamboo, a Chinese state-affiliated threat actor, using a pl...
Analysis Summary
# Threat Actor: BrazenBamboo
## Attribution & Identity
* **Attribution:** Chinese state-affiliated threat actor.
* **Known Aliases and Groups:** BrazenBamboo.
* **Associated Groups:** Shares overlapping C2 infrastructure and development methods with actors utilizing DEEPDATA, DEEPPOST, and LIGHTSPY malware families. Infrastructure analysis suggests development for governmental clients, potentially hinting at domestic surveillance operations.
## Activity Summary
BrazenBamboo was recently observed exploiting a zero-day vulnerability in Fortinet's FortiClient Windows VPN client. This exploitation allowed the actor to steal user credentials remaining in process memory after authentication. The observed objective of this specific campaign was likely data exfiltration.
## Tactics, Techniques & Procedures
* **Initial Access:** Exploitation of a zero-day vulnerability in Fortinet FortiClient (CVE/ID pending mention).
* **Execution/Defense Evasion:** Use of a custom plugin within their DEEPDATA malware specifically designed to target and extract credentials from the victim process memory.
* **Collection:** Stealing sensitive information, including credentials, chat data, and browser history (via DEEPDATA).
* **Exfiltration:** Using DEEPPOST malware for file transfer to remote servers over HTTPS.
* **MITRE ATT&CK IDs (Inferred based on description):** T1059 (Command and Scripting Interpreter), T1003 (OS Credential Dumping), T1567 (Exfiltration Over Web Service).
## Targeting
* **Sectors:** Not explicitly detailed in this context, but the reliance on VPN client exploits suggests targeting organizations utilizing Fortinet infrastructure for remote access.
* **Geography:** Not explicitly detailed.
* **Victims:** Organizations utilizing vulnerable versions of FortiClient for VPN access.
## Tools & Infrastructure
* **Malware Families Used:**
* **DEEPDATA:** Modular post-exploitation tool for Windows, capable of credential and data theft via a dedicated FortiClient extraction plugin.
* **DEEPPOST:** Focuses on data exfiltration via HTTPS.
* **LIGHTSPY:** Multi-platform malware (iOS, Android, macOS, and Windows) featuring enhanced C2 capabilities.
* **Infrastructure:** Overlapping C2 infrastructure shared between DEEPDATA and LIGHTSPY toolsets. Infrastructure shows evidence of domestic law enforcement references and multi-user support, suggesting governmental ties. (No specific IPs/URLs provided to defang).
## Implications
BrazenBamboo demonstrates a high level of technical sophistication, evidenced by their development and deployment of diverse, multi-platform malware and the timely exploitation of a vendor zero-day vulnerability (immediately prior to public disclosure). Their persistent development cycle and infrastructure designed for governmental servicing highlight them as a persistent, well-resourced threat actor focused on large-scale surveillance and data collection.
## Mitigations
* **Patch/Update:** Immediately apply vendor patches/updates for Fortinet FortiClient, particularly concerning the disclosed zero-day vulnerability related to process memory handling.
* **Memory Scanning:** Implement enhanced endpoint detection and response (EDR) capabilities capable of monitoring and alerting on anomalous credential access attempts within process memory space, specifically targeting VPN clients post-authentication.
* **Network Monitoring:** Monitor network traffic for known DEEPPOST exfiltration patterns (HTTPS data transfers).