THREAT OPS › Threat News › CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
<h1>CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT</h1> <p>One of the most common entry points for attackers is the exploitation of public-facing edge devices (such as VPNs, routers, and <a href="https://socradar.io/glossary/firewall/">firewalls</a>). Over the years, FortiGate firewalls have remained a consistent target, as evidenced by the recent widespread <a hre
MITRE ATT&CK techniques
- OS Credential DumpingT1003
- IP AddressesT1590.005
- JavaScriptT1059.007
- Email CollectionT1114
- Local Email CollectionT1114.001
- Domain AccountT1087.002
- VulnerabilitiesT1588.006
- SSHT1021.004
- Break Process TreesT1036.009
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- Exploit Public-Facing ApplicationT1190
- Credentials from Password StoresT1555
- Exfiltration Over Web ServiceT1567
- MasqueradingT1036
- Unsecured CredentialsT1552
- Process InjectionT1055
- Remote ServicesT1021
- Credentials from Web BrowsersT1555.003
- LSASS MemoryT1003.001
- External ProxyT1090.002
- System Network Configuration DiscoveryT1016
- Account DiscoveryT1087
- ProxyT1090
- Command and Scripting InterpreterT1059
- Domain AccountT1136.002
- Indicator RemovalT1070
- File and Directory DiscoveryT1083
- Portable Executable InjectionT1055.002
- Web ServiceT1102
- Credentials In FilesT1552.001
- PowerShellT1059.001
- Multi-hop ProxyT1090.003
- Unix ShellT1059.004
- Obfuscated Files or InformationT1027
- Encrypted ChannelT1573
- ExploitsT1587.004
- CredentialsT1589.001
- Asymmetric CryptographyT1573.002
- Exfiltration to Cloud StorageT1567.002
- File DeletionT1070.004
- Web ProtocolsT1071.001
- Network Service DiscoveryT1046
- Ingress Tool TransferT1105
- Remote Desktop ProtocolT1021.001
- Develop CapabilitiesT1587
- Internal ProxyT1090.001
- Develop CapabilitiesAML.T0017
- Exploit Public-Facing ApplicationAML.T0049
- Command and Scripting InterpreterAML.T0050
- Unsecured CredentialsAML.T0055
- Reverse ShellAML.T0072
- MasqueradingAML.T0074
Indicators of compromise
- 2d338ffc8cc80293575c6800c059e33eb41e967907c20ba7687b2231c50837dbsha256
- cc7f0660d56405cbdff157033d3e35305f063e62efaff6501d11e6a34e7bd151sha256
- eb4d8aab4e687839c5478a7a3819b0a7a857555ed50fc159c026e99764a0c8a0sha256
- fe7da807a2b37a2bbd8c27830a9acc0d86ad8128f38489c493873c7e410c0408sha256
- d99fa14f5e7dfe17e437f167f3f9550ebeda496960710dde81d41748bd7749e4sha256
- 005e6014fb8fd47249691756f5af3b3d53bfae82df88a71277e53e13fe94cb9fsha256
- 550f99193f9e90d93b70af1ab050a2d44f1830259ea165568dafc518e761c589sha256
- 08fa6abac9c132deff4f120a7fcfe5bf17c797b87dbbc3f261d5cf0c077c0a2esha256
- a9bea5f89984d47dd60216b0a0b064e8c7e8057e0c10509faa4a2d8d641eb73bsha256
- 1bf2c5976f2abbe147ae7be140ed69af2c25092f563786400aecd0231229be19sha256
- c25a27b506fbae62010caf2abff699df5c94d29f056fa7ccfb5f3170d917c8cbsha256
- d4911736986cf8affb29106fb8e8b74e00e52d5f762dce9025f2cfe431cf2140sha256
- CVE-2025-25249cve
- CVE-2024-47575cve
- CVE-2026-35273cve
- CVE-2024-26304cve
- https://fortiguard.fortinet.com/psirt/FG-IR-25-084url
- https://blog.n0p.me/2026/08/2026-08-21-fortitool-fortios-decryption/url
- https://hacktricks.wiki/en/binary-exploitation/libc-heap/unlink-attack.htmlurl
- 146.103.99.177ipv4
- 46.151.29.58ipv4
- 45.138.16.182ipv4
- 89.217.174.207ipv4
- 10.0.0.0/24cidr
- 10.0.1.0/24cidr
- 172.16.0.0/24cidr
- 192.168.0.0/24cidr
- 192.168.1.0/24cidr
Original source: https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/