Attackers Leverage FortiWeb Vulnerabilities to Deploy Sliver C2 for Long-Term Access
Threat researchers have identified a sophisticated attack campaign targeting FortiWeb web application firewalls across several continents. The adversaries are deploying the Sliver command-and-control framework to establish persistent access and covert…
Threat researchers have identified a sophisticated attack campaign targeting FortiWeb web application firewalls across several continents. The adversaries are deploying the Sliver command-and-control framework to establish persistent access and covert proxy infrastructure.
The discovery resulted from analyzing exposed Sliver C2 databases and logs during routine threat hunting on Censys, revealing an operation exploiting vulnerabilities in outdated FortiWeb devices.
The threat actor gained initial access by exploiting vulnerabilities on multiple FortiWeb appliances, specifically targeting versions from 5.4.202 to 6.1.62. Evidence suggests the attacker utilized React2Shell (CVE-2025-55182) alongside undisclosed FortiWeb vulnerabilities.
The absence of proof-of-concept code for these exploits indicates the potential use of zero-day vulnerabilities or undisclosed weaponized exploits.
The investigation identified two primary C2 domains: ns1.ubunutpackages[.]store and ns1.bafairforce[.]army, both hosting Sliver instances. The threat actor created decoy websites impersonating legitimate services, including a fake Ubuntu Packages repository and a spoofed Bangladesh Air Force recruitment page.
C2 creation timestamps show the first domain registered in September 2024, with rapid victim onboarding between Dec 22-30, 2025, compromising 30 unique hosts in eight days.
Threat researchers have identified a sophisticated attack campaign targeting FortiWeb web application firewalls across several continents.
Persistence was established through systemd services and supervisor configuration modifications, disguising the Sliver binary as a system updater process at /bin/.root/system-updater.
The threat actor deployed Fast Reverse Proxy (FRP) and a disguised microsocks SOCKS proxy renamed as "cups-lpd," bound to port 515, to mimic the legitimate CUPS Line Printer Daemon, demonstrating considerable operational discipline.
Victimology analysis revealed targeted attacks in Pakistan and Bangladesh, particularly affecting financial and government sectors. The Bangladesh-themed decoy infrastructure aligns with victim locations, indicating a targeted rather than opportunistic operation.
The broader threat highlights a security blindspot: FortiWeb appliances and similar devices often lack built-in endpoint detection and response (EDR) capabilities, with organizations rarely deploying aftermarket security tools.
This research underscores a significant detection challenge. Organizations typically rely on centralized EDR solutions monitoring traditional endpoints, making appliance-level compromises largely invisible. The campaign was only uncovered because of accidentally exposed operational logs and databases, suggesting many similar attacks may remain undetected.
The findings emphasize the need for organizations to implement compensating controls on edge appliances, including security monitoring, vulnerability management for legacy device updates, and network segmentation to limit lateral movement from compromised perimeters.
The sophisticated use of renamed utilities and legitimate-looking services shows threat actors are adapting to evade detection in environments where traditional security tools offer limited visibility.
Based on reporting by GBHackers.
