Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Exploit DeepSeek and Claude AI to Launch Global Attacks on FortiGate Devices

Hackers are utilizing commercial AI models such as DeepSeek and Claude to automate attacks on FortiGate firewalls globally. These attacks are turning basic misconfigurations into extensive intrusion campaigns.

Hackers are utilizing commercial AI models such as DeepSeek and Claude to automate attacks on FortiGate firewalls globally. These attacks are turning basic misconfigurations into extensive intrusion campaigns.

In February 2026, a misconfigured SimpleHTTP server was found exposing over 1,400 files and 139 subdirectories, including stolen FortiGate configurations, Active Directory maps, credential dumps, exploit code, and attack playbooks.

The infrastructure, hosted in Switzerland, was identified in Hunt.io’s Attack Capture as an active command-and-control and staging point. The data showed confirmed intrusions in an industrial gas company in the Asia-Pacific region, a telecom provider in Turkey, and a large media company in Asia, with reconnaissance on targets in South Korea, Egypt, Vietnam, and Kenya.

Historical telemetry indicated the same host had previously exposed a similar open directory in December 2025, containing many of the same tools plus additional victim data.

Logs and SSH histories confirmed the server was actively modifying FortiGate configurations on appliances in various countries, indicating its role in live attacks.

The AI models were used to scale routine post-compromise activities. DeepSeek processed reconnaissance output and FortiGate backup configurations to generate structured attack plans, while Claude’s coding agent produced vulnerability assessment reports during active intrusions, running offensive tooling scripts with minimal human intervention.

A custom Model Context Protocol (MCP) server named ARXON acted as a bridge between collected data and the language models, maintaining a growing knowledge base per target. ARXON automated processes such as ingesting stolen VPN and FortiGate configs, deriving internal topology, and coordinating attack plans.

Hackers are utilizing commercial AI models such as DeepSeek and Claude to automate attacks on FortiGate firewalls globally.
Joseph Cain · Thehackingpost

Another component, CHECKER2, orchestrated parallel VPN scanning and target processing, with logs indicating over 2,500 FortiGate appliances across more than 100 countries were targeted for automated access attempts.

The most detailed documentation was found in an intrusion at an industrial gas company, where attackers accessed a FortiGate-40F branch firewall to extract a full configuration backup.

Custom MCP Tooling and Rapid Evolution

ARXON and CHECKER2 formed the backbone of the operation, allowing the management of numerous FortiGate-centric intrusions. ARXON hosted scripts to automate VPN account creation, firewall policy adjustments, and Domain Admin privilege testing.

In December 2025, an earlier phase of the operation utilized HexStrike, an open-source MCP framework, allowing models to control penetration-testing tools. By February, the operator transitioned to custom ARXON and CHECKER2 components, indicating a shift towards a fully automated exploitation pipeline.

Threat intelligence reports link this infrastructure to a Russian-speaking actor who compromised over 600 FortiGate firewalls in at least 55 countries between January and February 2026, primarily through exposed management interfaces and weak credentials.

Advertisement

Defense priorities include reducing attack surfaces by closing public FortiGate management ports, enforcing strong MFA, and patching widely exploited Fortinet flaws. Continuous monitoring for unauthorized VPN accounts and policy changes is critical to counter AI-driven workflows.

IP Address Domain ASN

212.11.64[.]250:9999 N/A Global-Data System IT Corporation

185.196.11[.]225 N/A Global-Data System IT Corporation

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories