FortiGate Post-Exploitation RAT, PivotC2 Spotted by SOCRadar

The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon. Successful exploitation delivers PivotC2, a Node.js RAT designed specifically as a FortiGate post-exploitation tool. PivotC2 supports features such as interactive shells, tunneling, network scanning, and configuration harvesting.

Based on the observed inline comments and usage guidance, the actors highly likely leveraged AI to develop the RAT. Active exploitation has been observed since at least July 2026 and is still ongoing. The threat actors targeted more than 30,000 IP addresses, leading to the exploitation and infection of 178 devices with PivotC2.

For full details, the analysis of this post-exploitation RAT can be read here: https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading