#FortiGuardLabs is the global threat intelligence and research organization of @Fortinet.

Sunnyvale, CA
Looks legitimate. Runs legitimate. Carries a RAT. 🎭 Our team investigated a #SectopRAT variant concealed inside legitimate software and unpacked through a multi-stage loader before executing in memory. Once active, it gives attackers broad remote control, including screen capture, file and process management, command execution, and access to sensitive data from browsers, email clients, gaming platforms, and crypto wallets. πŸ”— See how the payload stays hidden and what it can do: ow.ly/QvuS50ZR8Hz
1
2
433
WORKFLOW STATUS: APPROVED βœ… AUTHENTICATION: NOT REQUIRED 🚫 RESULT: OS COMMAND EXECUTION 🚨 That is the problem with CVE-2026-58138. #FortiGuardLabs is seeing active attack attempts against vulnerable Orkes Conductor deployments, where malicious workflow definitions can escape the intended scripting environment and execute commands on the underlying server. πŸ”— Get the technical analysis: ow.ly/5SM150ZPb1l
1
1
3
746
FortiGuard Labs retweeted
For years, anonymity has worked in the cybercriminal's favor. What changes when it doesn't? @FortiGuardLabs Derek Manky and @CSIWorld's Hayley van Loon discuss how the Cybercrime Bounty program is designed to raise the cost of operating in the shadows by giving people a trusted, anonymous way to share what they know. The goal goes beyond disruption: accountability and deterrence. πŸ”— See how Operation Silent Vector I is putting that model into action: ow.ly/njaL50ZO3yX
2
8
2,099
FortiGuard Labs retweeted
At @INTERPOL_HQ's 11th Americas Working Group on Cybercrime for Heads of Unit, Fortinet's Arturo E. Torres joined INTERPOL, the World Economic Forum (@wef) and Paraguayan authorities around a practical question: How do we turn threat intelligence into coordinated action across Latin America? πŸ’¬ This new blog shares how @FortiGuardLabs intelligence supports investigations and operations, and why disruption, not information sharing alone, is the real measure of public-private collaboration. πŸ”— Read Arturo's perspective: ow.ly/gA5t50ZNT0L
2
6
1,876
Casbaneiro is getting harder to read on purpose. πŸ•΅οΈβ€β™‚οΈ #FortiGuardLabs uncovered a new campaign targeting Latin America that uses geofencing, staged loaders, selective activation, and separate servers for stolen data to make the #malware appear inactive or inaccessible during analysis. πŸ”— Explore the attack chain: ow.ly/4pyo50ZMbSc
615
Someone else may be spending your AI budget. πŸ’ΈπŸ€– #FortiGuardLabs analyzed an Amazon Bedrock LLMjacking incident where a leaked AWS IAM key was used to create a new identity, subscribe to foundation models, and generate inference charges on the victim’s account. Valid access. Real cost. πŸ”— See how to spot LLMjacking: ow.ly/SFzZ50ZKIAl
545
🚨 New #FortiGuardLabs Outbreak Alert: WordPress Core Unauthenticated RCE The WP2Shell attack chain combines two critical vulnerabilities to enable remote code execution against vulnerable WordPress installations without authentication or user interaction. Read the latest and sign up for outbreak alerts today: ow.ly/gHWK50ZIUYl
1
711
FortiGuard Labs retweeted
As a founding partner of @FIRSTdotOrg, #Fortinet is helping expand training, cyber drills, regional engagement, and incident response readiness where it can make the greatest impact. This is capacity building, not just technology. It's investing in the people, skills, and relationships behind coordinated response. Great to see Derek Manky, our Chief Security Strategist and Global VP of Threat Intelligence at @FortiGuardLabs, featured in FIRST's video series on this work. πŸ”— See what global collaboration looks like in practice: ow.ly/vrua50ZIRtM
3
8
2,051
FortiGuard Labs retweeted
From access brokers and botnets to ransomware affiliates and scam networks, @INTERPOL_HQ's African Cyberthreat Assessment Report 2026 shows a more specialized, automated, and borderless threat landscape. β†’ AI is accelerating attacks. β†’ Credentials remain a key target. β†’ Cybercrime-as-a-Service lowers barriers. β†’ Collaboration enables disruption. With contributions from @FortiGuardLabs, the report reinforces the need for coordinated intelligence sharing and public-private partnerships. πŸ”— Read the analysis: ow.ly/swlO50ZIjGY
2
8
1,856
🚨 New #FortiGuardLabs Outbreak Alert: QuickFox Supply Chain Attack A trojanized Windows installer turned a trusted software path into a selective delivery mechanism for the FDMTP backdoor. Read more: ow.ly/6GYu50ZFpsc
2
613
FortiGuard Labs retweeted
🌎 In this week's "Improving Security Across Nations with @FIRSTdotOrg" video series, we spotlight Derek Manky, Chief Security Strategist and Global VP of Threat Intelligence at @Fortinet, and FIRST CORE Founding Partner. Watch here: go.first.org/3GtbN #cybersecurity
4
7
694
Mirai evolved. So did the risk. 🐧 Our researchers are tracking Evooo1Bot, a previously undocumented #Linux botnet that expands the familiar Mirai framework with a far more capable toolkit. β†’ Exploit exposed devices β†’ Steal credentials β†’ Scan for SSH access β†’ Turn compromised infrastructure into a proxy πŸ”— Read the technical analysis: ow.ly/kgJc50ZzzAr
4
7
1,290
FortiGuard Labs retweeted
Detecting cybercrime is one thing. Identifying the people behind it is another. πŸ” At #BHUSA, Fortinet's Derek Manky spoke with @theCUBE about closing that accountability gap through the Cybercrime Bounty program with Crime Stoppers International. β†’ Trusted, anonymous reporting β†’ Human intelligence, not just technical indicators β†’ Turning validated tips into actionable intelligence ⏯️ Watch the full interview: ow.ly/VNh350ZyB5N
1
2
19
2,466
The threat wasn’t hiding behind the download... It was inside it. 🦊 ⚠️ #FortiGuardLabs researchers uncovered a long-running supply chain attack in which a trojanized QuickFox Windows installer selectively profiled targets before deploying the FDMTP backdoor. πŸ”— Read the coverage from The Hacker News: ow.ly/pLXo50ZyIRU
1
3
5
1,715
There’s a hidden passenger in this shortcut. 🦊⚠️ Our team uncovered a long-running supply chain attack that used a trojanized #QuickFox application to identify select Windows targets and deploy the FDMTP implant for persistent access. πŸ”— See how the campaign operated: ow.ly/S15A50Zwl46 #FortiGuardLabs
1
4
771
TOMORROW: Black Hat 2026 is on! 🎰 Join #FortiGuardLabs in Las Vegas for a look at what threat intelligence is seeing next as AI-enabled adversaries raise the stakes for defenders. πŸ—“οΈ August 4-6, 2026 πŸ”— Get connected today: ow.ly/SaoE50ZvXiT #BHUSA
4
608
TrickBot is changing how it hides in plain sight. πŸ•΅οΈβ€β™‚οΈ 🌐 Our team examines a variant that replaces traditional HTTP-based command-and-control with DNS tunneling, embedding encrypted data inside malformed DNS traffic. See how it maintains persistence, evades analysis, and executes malicious modules in memory. πŸ”— Read the analysis: ow.ly/I6N150ZtEgh
3
599
A .ttf file may not be a font at all. ⌨️ πŸ” A large-scale campaign is disguising low-detection Lua loaders as font files to deploy RATs and infostealers, including Agent Tesla, Remcos, XWorm, and Snake Keylogger. See how the infection chain works and how attackers are evolving it to evade detection. πŸ”— Read the analysis: ow.ly/pr7Z50Zrxpq
1
3
572
The next wave of AI threats is already taking shape. Join #FortiGuardLabs at Black Hat 2026 for a look at what threat intelligence is seeing next, from AI-enabled adversaries to the rise of autonomous defense. 🎀 Speaker: Aamir Lakhani, Sr. Director, AI and Threat Research πŸ—“οΈ August 5, 2026 πŸ•œ 1:30 PM Get connected today: ow.ly/eZ9l50ZqcaN
1
4
591
This Trojan checks your location before opening the door. πŸšͺ🏦 Our #FortiGuard researchers analyzed an ongoing Ousaban campaign targeting banking users in Spain and Portugal. πŸ‘‰ One small detail defenders should not miss: the campaign uses daily-changing domains to reach C2 infrastructure. Read the latest threat analysis: ow.ly/GTSR50ZjU8i
1
4
499