Threat actors are exploiting a high-severity RCE vulnerability in Fortinet products to deploy the AI-developed PivotC2 RAT. Over 30,000 IP addresses were targeted, leading to significant data exfiltration in US entities.
- CVE-2025-25249 is a heap-based buffer overflow vulnerability allowing unauthenticated RCE.
- Attackers are deploying PivotC2, a Node.js-based RAT likely developed using AI.
- Over 178 devices have been infected, primarily targeting US-based organizations.
- CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog.
Cybersecurity researchers at SOCRadar have uncovered a sophisticated campaign where threat actors are leveraging a critical security loophole in Fortinet products. The vulnerability, identified as CVE-2025-25249, is a heap-based buffer overflow that permits remote, unauthenticated attackers to execute arbitrary commands on targeted systems. While a patch was released in January 2026, many organizations remain vulnerable, providing a gateway for malicious actors.
The primary objective of these attacks is the deployment of the PivotC2 RAT (Remote Access Trojan). Built using Node.js, this backdoor is specifically designed for post-exploitation on FortiGate devices. Once installed, it grants attackers an interactive shell, the ability to tunnel traffic, scan internal networks, and harvest sensitive configuration data, effectively turning the security appliance into a surveillance tool for the hacker.
Why This Matters
BozokMedia analysis shows that the integration of AI in malware development is no longer theoretical. The fact that PivotC2 was likely developed with AI assistance indicates a shift toward faster, more polymorphic threat creation. When security hardware—which is supposed to be the first line of defense—becomes the entry point, the entire corporate trust model collapses.
The transition of AI from a defensive tool to an offensive weapon in RAT development marks a dangerous escalation in cyber warfare.
The scale of the operation is alarming. SOCRadar reports that hackers targeted more than 30,000 IP addresses, successfully infecting 178 devices. The campaign appears to be orchestrated by Russian-speaking cybercrime actors, with at least two confirmed cases of data exfiltration from US-based entities. This highlights a geopolitical dimension to the exploitation of enterprise-grade networking gear.
In response to the active exploitation, the Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2025-25249 to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies have been mandated to apply patches within a strict three-day window to prevent further national security compromises.
| Product | Affected Versions | Patched Versions |
|---|---|---|
| FortiOS | Multiple Legacy Versions | 7.6.4, 7.4.9, 7.2.12, 7.0.18 |
| FortiSwitchManager | Multiple Legacy Versions | 7.2.7, 7.0.6 |
Frequently Asked Questions
Q: How can I tell if my Fortinet device is infected with PivotC2?
A: Organizations should monitor for unusual outbound traffic tunneling and check for unauthorized interactive shell sessions in their system logs.
Q: Is this vulnerability only affecting US companies?
A: While the primary targets identified were US entities, the vulnerability exists globally in all unpatched versions of the affected Fortinet software.