Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC5820

Also known as: 2024, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, CVE-2024-37383

Description

UNC5820 was identified when multiple organizations reported unauthorized activity on their FortiManager consoles. By leveraging CVE‑2024‑47575, a flaw that bypasses authentication controls, the actor can remotely execute arbitrary commands with administrator privileges across managed FortiGate firewalls. During these sessions, it retrieves device configuration data and user credentials, harvesting FortiOS256 password hashes for later offline cracking or resale. Once inside the appliance environment, UNC5820 performs limited post‑exploitation tasks: exfiltration of collected artifacts over standard application layer protocols (primarily HTTP/HTTPS) and temporary persistence via custom backdoor components. Though no lateral movement into corporate networks has been observed to date, the ability to pivot from FortiGate devices to higher‑value assets remains a future risk. Financial gain appears to be the primary motive—whether through direct data monetization or ransom leverage—but state sponsorship cannot be ruled out given the sophistication of the zero‑day exploitation. The actor’s use of known tools such as PowerShell, netsh, and possibly a Havex RAT footprint indicates familiarity with both native Windows tooling and commercial RAT infrastructure.

Goals & Targeting

Targeted Sectors

Media
Defense
Financial services
Government
Manufacturing
Information technology

AI Analysis

Grounded in web research
· 13 hours ago

Executive Summary

UNC5820 is a financially driven threat actor that exploits the Fortinet FortiManager zero‑day vulnerability CVE‑2024‑47575 to gain unauthenticated remote code execution. They harvest configuration files and FortiOS256 hashed passwords from compromised FortiGate devices, but have not yet demonstrated lateral movement or broader infrastructure compromise. The actor’s activities affect media, defense, financial services, government, manufacturing, and IT sectors worldwide via the widespread deployment of Fortinet appliances.

Goals & Targeting

UNC5820 targets organizations that heavily rely on Fortinet security appliances, spanning government, defense, financial services, media, manufacturing, and IT sectors. The actor exploits the commonality of FortiManager within multi‑site deployments to gain early footholds and harvest privileged configuration data. By acquiring hashed passwords and network settings, they potentially enable credential reuse or brute‑force attacks against other systems, aligning with a purely revenue‑driven agenda that prioritizes high‑value, easily monetizable assets.

Enhanced Description

Key Capabilities

  • Zero‑day exploitation of FortiManager (CVE‑2024‑47575) to achieve remote command execution
  • Privilege escalation to full administrator on FortiGate devices
  • Collection and exfiltration of configuration files, user data, and hardware password hashes
  • Use of PowerShell scripts for post‑exploitation persistence and credential dumping
  • Deployment of custom or commercial RAT components (e.g., Havex RAT) for extended control

MITRE ATT&CK Tactics

Initial Access
Execution
Command and Control
Privilege Escalation
Credential Access
Exfiltration

ATT&CK Techniques

T1190: Exploit Public-Facing Application
T1071.001: Web Protocols
T1059.003: Command & Scripting Interpreter ‑ PowerShell
T1105: Ingress Tool Transfer
T1020: Automated Exfiltration
T1560.001: Archive Collected Data

Software / Tooling

Custom Exploit Kit for CVE‑2024‑47575
Havex RAT
PowerShell
netsh

Campaigns & Victims

The actor surfaced in early 2024 during a wave of Fortinet vulnerability exploits. While the initial findings centered on configuration and credential theft, no evidence yet exists of broader lateral movement or large‑scale ransomware attacks. UNC5820’s methodology shows an evolving campaign: starting with zero‑day exploitation, moving to data exfiltration, and potentially scaling to other systems if foothold is established. Their focus on multi‑site FortiManager deployments suggests a strategic interest in enterprises where compromise can yield high‑value data across multiple connected networks.

IOC Patterns

  • Exploitation of CVE‑2024‑47575 in FortiManager
  • Outbound HTTP/HTTPS connections to command & control servers such as demo-cloud.space and cisa.gov (placeholder domains)
  • Execution of PowerShell scripts for post‑exploitation activities
  • Collection of configuration files and FortiOS256 password hashes
  • Use of suspicious IPs (e.g., 45.32.41.202, 104.238.141.143) for exfiltration traffic

Recommended Actions

  • Secure FortiManager firmware by applying the latest security patches from Fortinet promptly.
  • Implement network segmentation so that managed FortiGate appliances are isolated from critical corporate infrastructure. Enable endpoint monitoring on FortiGateway devices to detect anomalous command execution and file transfers. Adopt multi‑factor authentication (MFA) for managing FortiManager consoles to mitigate unauthorized access & post‑exploitation impact. Deploy IDS/IPS solutions capable of detecting abnormal HTTP traffic, credential dumping signatures, and known backdoor C2 patterns. Regularly audit device configuration backups and password hash integrity; Conduct a vulnerability assessment focusing on zero‑day CVEs such as CVE‑2024‑47575.

Suggested Tags

APT
Financial Gain
Privilege Escalation
Infrastructure Exploitation
Remote Code Execution
Credential Dumping
Fortinet
FortiManager
Zero-Day Vulnerability

Confidence Assessment

Confidence is moderate. Primary evidence comes from a single Malpedia actor profile (https://malpedia.caad.fkie.fraunhofer.de/actor/unc5820) and associated tool page for Havex RAT (https://malpedia.caad.fkie.fraunhofer.de/details/win.havex_rat). The actor’s activities are corroborated by reported Exploit of FortiManager CVE‑2024‑47575, but detailed operation data, such as precise tactics beyond exfiltration or broader malware usage, is limited. Open gaps include the exact geographic location of the operators, their full toolchain beyond standard Windows utilities, and evidence of subsequent lateral expansion.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. www.loginsoft.com — Cited by web research for: CVE-2024-37383
  3. cloud.google.com — Cited by web research for: Leverage
  4. attack.mitre.org — Cited by web research for: PowerShell
  5. https://malpedia.caad.fkie.fraunhofer.de/actor/unc5820 — Cited by AI analysis.
  6. https://malpedia.caad.fkie.fraunhofer.de/details/win.havex_rat — Cited by AI analysis.

Intel Summary

46

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

14

Tactics

Tags

APT
Critical Infrastructure
Data Exfiltration
cyber_espionage
Fortinet
vulnerability_exploit
Financial Gain
Privilege Escalation
Infrastructure Exploitation
Remote Code Execution
Credential Dumping
FortiManager
Zero-Day Vulnerability

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
North Korea (KP)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.