Also known as: 2024, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, CVE-2024-37383
UNC5820 was identified when multiple organizations reported unauthorized activity on their FortiManager consoles. By leveraging CVE‑2024‑47575, a flaw that bypasses authentication controls, the actor can remotely execute arbitrary commands with administrator privileges across managed FortiGate firewalls. During these sessions, it retrieves device configuration data and user credentials, harvesting FortiOS256 password hashes for later offline cracking or resale. Once inside the appliance environment, UNC5820 performs limited post‑exploitation tasks: exfiltration of collected artifacts over standard application layer protocols (primarily HTTP/HTTPS) and temporary persistence via custom backdoor components. Though no lateral movement into corporate networks has been observed to date, the ability to pivot from FortiGate devices to higher‑value assets remains a future risk. Financial gain appears to be the primary motive—whether through direct data monetization or ransom leverage—but state sponsorship cannot be ruled out given the sophistication of the zero‑day exploitation. The actor’s use of known tools such as PowerShell, netsh, and possibly a Havex RAT footprint indicates familiarity with both native Windows tooling and commercial RAT infrastructure.
Targeted Sectors
Executive Summary
UNC5820 is a financially driven threat actor that exploits the Fortinet FortiManager zero‑day vulnerability CVE‑2024‑47575 to gain unauthenticated remote code execution. They harvest configuration files and FortiOS256 hashed passwords from compromised FortiGate devices, but have not yet demonstrated lateral movement or broader infrastructure compromise. The actor’s activities affect media, defense, financial services, government, manufacturing, and IT sectors worldwide via the widespread deployment of Fortinet appliances.
Goals & Targeting
UNC5820 targets organizations that heavily rely on Fortinet security appliances, spanning government, defense, financial services, media, manufacturing, and IT sectors. The actor exploits the commonality of FortiManager within multi‑site deployments to gain early footholds and harvest privileged configuration data. By acquiring hashed passwords and network settings, they potentially enable credential reuse or brute‑force attacks against other systems, aligning with a purely revenue‑driven agenda that prioritizes high‑value, easily monetizable assets.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The actor surfaced in early 2024 during a wave of Fortinet vulnerability exploits. While the initial findings centered on configuration and credential theft, no evidence yet exists of broader lateral movement or large‑scale ransomware attacks. UNC5820’s methodology shows an evolving campaign: starting with zero‑day exploitation, moving to data exfiltration, and potentially scaling to other systems if foothold is established. Their focus on multi‑site FortiManager deployments suggests a strategic interest in enterprises where compromise can yield high‑value data across multiple connected networks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is moderate. Primary evidence comes from a single Malpedia actor profile (https://malpedia.caad.fkie.fraunhofer.de/actor/unc5820) and associated tool page for Havex RAT (https://malpedia.caad.fkie.fraunhofer.de/details/win.havex_rat). The actor’s activities are corroborated by reported Exploit of FortiManager CVE‑2024‑47575, but detailed operation data, such as precise tactics beyond exfiltration or broader malware usage, is limited. Open gaps include the exact geographic location of the operators, their full toolchain beyond standard Windows utilities, and evidence of subsequent lateral expansion.
No campaigns linked yet.
No observed data linked yet.
46
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
14
Tactics