Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Attackers Leverage FortiWeb Vulnerabilities to Deploy Sliver C2 for Long-Term Access

Threat researchers have identified a sophisticated attack campaign targeting FortiWeb web application firewalls across several continents. The adversaries are deploying the Sliver command-and-control framework to establish persistent access and covert…

Threat researchers have identified a sophisticated attack campaign targeting FortiWeb web application firewalls across several continents. The adversaries are deploying the Sliver command-and-control framework to establish persistent access and covert proxy infrastructure.

The discovery resulted from analyzing exposed Sliver C2 databases and logs during routine threat hunting on Censys, revealing an operation exploiting vulnerabilities in outdated FortiWeb devices.

The threat actor gained initial access by exploiting vulnerabilities on multiple FortiWeb appliances, specifically targeting versions from 5.4.202 to 6.1.62. Evidence suggests the attacker utilized React2Shell (CVE-2025-55182) alongside undisclosed FortiWeb vulnerabilities.

The absence of proof-of-concept code for these exploits indicates the potential use of zero-day vulnerabilities or undisclosed weaponized exploits.

The investigation identified two primary C2 domains: ns1.ubunutpackages[.]store and ns1.bafairforce[.]army, both hosting Sliver instances. The threat actor created decoy websites impersonating legitimate services, including a fake Ubuntu Packages repository and a spoofed Bangladesh Air Force recruitment page.

C2 creation timestamps show the first domain registered in September 2024, with rapid victim onboarding between Dec 22-30, 2025, compromising 30 unique hosts in eight days.

Threat researchers have identified a sophisticated attack campaign targeting FortiWeb web application firewalls across several continents.
Megan Forbes · Thehackingpost

Persistence was established through systemd services and supervisor configuration modifications, disguising the Sliver binary as a system updater process at /bin/.root/system-updater.

The threat actor deployed Fast Reverse Proxy (FRP) and a disguised microsocks SOCKS proxy renamed as "cups-lpd," bound to port 515, to mimic the legitimate CUPS Line Printer Daemon, demonstrating considerable operational discipline.

Victimology analysis revealed targeted attacks in Pakistan and Bangladesh, particularly affecting financial and government sectors. The Bangladesh-themed decoy infrastructure aligns with victim locations, indicating a targeted rather than opportunistic operation.

The broader threat highlights a security blindspot: FortiWeb appliances and similar devices often lack built-in endpoint detection and response (EDR) capabilities, with organizations rarely deploying aftermarket security tools.

Advertisement

This research underscores a significant detection challenge. Organizations typically rely on centralized EDR solutions monitoring traditional endpoints, making appliance-level compromises largely invisible. The campaign was only uncovered because of accidentally exposed operational logs and databases, suggesting many similar attacks may remain undetected.

The findings emphasize the need for organizations to implement compensating controls on edge appliances, including security monitoring, vulnerability management for legacy device updates, and network segmentation to limit lateral movement from compromised perimeters.

The sophisticated use of renamed utilities and legitimate-looking services shows threat actors are adapting to evade detection in environments where traditional security tools offer limited visibility.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories