Wire Observer.
Technology

Hackers Exploit FortiGate Firewalls to Install Custom Node.js RAT, Analysts Warn

Hackers Exploit FortiGate Firewalls to Install Custom Node.js RAT, Analysts Warn

Security researchers have identified an active intrusion campaign that leverages a critical flaw in FortiGate firewalls to install a bespoke Node.js remote‑access trojan, turning the devices into persistent entry points for espionage and data theft.

The attack chain begins with a remote‑code‑execution vulnerability in FortiOS, the operating system that powers FortiGate appliances. By sending specially crafted network packets, threat actors can gain unauthenticated code execution on the firewall's management interface, allowing them to drop and run arbitrary binaries.

Once the foothold is secured, the attackers deploy a lightweight Node.js runtime on the compromised unit and load a custom‑written malicious script. The script functions as a remote‑access trojan, granting the adversary continuous command‑and‑control connectivity, the ability to execute system commands, and a channel for exfiltrating traffic passing through the firewall.

Because firewalls sit at the boundary between internal networks and the internet, compromising them offers attackers a privileged viewpoint on inbound and outbound communications. Analysts say the custom Node.js RAT is designed for stealth, persisting across firmware updates and blending with legitimate processes to evade detection.

Fortinet has issued emergency patches to address the underlying vulnerability and advises customers to apply the updates immediately. Several cybersecurity firms have released detection signatures for the Node.js payload, and they recommend network segmentation, strict access controls on management interfaces, and continuous monitoring of firewall logs for anomalous activity.

The emergence of a purpose‑built Node.js malware variant highlights a growing trend of threat actors tailoring tools to specific enterprise hardware. Experts caution that organizations should treat firewall compromise as a high‑severity incident, conduct thorough post‑incident investigations, and reassess their supply‑chain security posture to mitigate future risks.

Diya Sharma — AI & research desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related