Mitigation Advice
Fortinet has identified the potentially compromised systems, and we are proactively contacting impacted customers. To defend against this malicious cyber activity, Fortinet recommends that customers with impacted FortiGate appliances to immediately:
- Terminate all admin and VPN sessions and reset credentials. Terminate all active administrative sessions. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems, and enforce strong password policies.
- Implement MFA on all administrator and VPN user accounts.
- Upgrade to latest versions of 7.4, 7.6, or 8.0. These versions support PBKDF2 hashing of administrator credentials. Follow the guidance to remove older legacy password settings via set login-lockout-upon-weaker-encryption.
- Validate configuration. Review firewall and VPN users and other configuration for unauthorized changes. Preferably compare to a known good configuration. Pay particular attention to the addition of unrecognized accounts, such as βforticloud, fortiuser, fortinet-support, fortinet-tech-support,β etc.
- Check your logs. Look for unexpected administrator access from unknown IP and domain controller logs for lateral movement, unusual access, suspicious accounts, or unauthorized configuration changes.
- Reduce your attack surface and lock down management access. Restrict external management of your devices via trusted hosts (good), a local-in policy (better), or remove internet administration altogether (best).