The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon. Successful exploitation delivers PivotC2, a Node.js RAT designed specifically as a FortiGate post-exploitation tool. PivotC2 supports features such as interactive shells, tunneling, network scanning, and configuration harvesting.
Based on the observed inline comments and usage guidance, the actors highly likely leveraged AI to develop the RAT. Active exploitation has been observed since at least July 2026 and is still ongoing. The threat actors targeted more than 30,000 IP addresses, leading to the exploitation and infection of 178 devices with PivotC2.
For full details, the analysis of this post-exploitation RAT can be read here: https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
Related
This entry was posted on September 8, 2026 at 11:14 am and is filed under Commentary with tags SOC Radar. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
FortiGate Post-Exploitation RAT, PivotC2 Spotted by SOCRadar
The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon. Successful exploitation delivers PivotC2, a Node.js RAT designed specifically as a FortiGate post-exploitation tool. PivotC2 supports features such as interactive shells, tunneling, network scanning, and configuration harvesting.
Based on the observed inline comments and usage guidance, the actors highly likely leveraged AI to develop the RAT. Active exploitation has been observed since at least July 2026 and is still ongoing. The threat actors targeted more than 30,000 IP addresses, leading to the exploitation and infection of 178 devices with PivotC2.
For full details, the analysis of this post-exploitation RAT can be read here: https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
Share this:
Like this:
Related
This entry was posted on September 8, 2026 at 11:14 am and is filed under Commentary with tags SOC Radar. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.