FortiGuardLabs Profile Banner
FortiGuard Labs Profile
FortiGuard Labs

@FortiGuardLabs

Followers
41K
Following
8K
Media
2K
Statuses
4K

#FortiGuardLabs is the global threat intelligence and research organization of @Fortinet.

Sunnyvale, CA
Joined May 2011
Don't wanna be here? Send us removal request.
@FortiGuardLabs
FortiGuard Labs
15 hours
🕵️‍♂️ 📁 New infostealer alert: NordDragonScan. We uncovered an active campaign using a weaponized HTA script to silently drop NordDragonScan into victim environments that copies and harvests sensitive documents and browser profiles. 🔎 Read our full threat analysis:
0
1
3
@FortiGuardLabs
FortiGuard Labs
6 days
⚠️ A new botnet threat is on the rise. Our researchers have uncovered #RondoDox, a stealthy #malware campaign that mimics gaming and VPN traffic to evade detection—while maintaining persistent access to compromised systems. 📖 Read the full analysis and protection guidance:
1
1
4
@FortiGuardLabs
FortiGuard Labs
13 days
🎣 📧 Our #FortiMail IR team uncovered a new #phishing campaign targeting organizations in Colombia—disguised as official government communication. The attack leverages DCRAT, a Remote Access Trojan, using:. 🎭 Government impersonation.🧬 Steganography & obfuscation.📁
0
3
8
@FortiGuardLabs
FortiGuard Labs
20 days
🥷 This stealthy #Havoc variant shows how far attackers will go to stay hidden inside critical infrastructure. Our researchers analyzed a malicious Havoc sample used in a long-term intrusion targeting Middle East CNI—injecting into cmd.exe via a disguised conhost.exe, and
1
3
8
@FortiGuardLabs
FortiGuard Labs
26 days
🎣 📩 This new #phishing campaign will make you think twice before opening that tax email…. Our team uncovered evolving malware activity targeting Microsoft Windows users in Taiwan—including Winos 4.0—disguised as tax-related emails. The goal? Steal data for future attacks.
0
3
7
@FortiGuardLabs
FortiGuard Labs
1 month
📂 One outdated Office app. One click. Full device compromise. Our team just uncovered a phishing campaign exploiting CVE-2017-0199 to drop FormBook #malware via Excel files—stealing credentials, keystrokes, and more. Details + IOCs: ←
0
3
6
@FortiGuardLabs
FortiGuard Labs
2 months
🛑 📩 New #ransomware threat: VanHelsing. This #RansomwareRoundup highlights a high-severity variant targeting Microsoft Windows systems with file encryption, ransom demands, and public data leaks. 🔗 Read the full breakdown: ←
0
2
10
@FortiGuardLabs
FortiGuard Labs
2 months
🎣 📩 #Phishing, persistence, and payloads—Horabot hits hard across Latin America. We recently observed a surge in Horabot malware campaigns, delivered via fake Spanish-language invoice emails targeting Spanish-speaking users. Full breakdown: 🔍
0
3
11
@FortiGuardLabs
FortiGuard Labs
2 months
🚨 Just in: Our #FortiMail IR team uncovered a sophisticated RATty #malware campaign targeting Spain, Italy, and Portugal—bypassing filters with SPF evasion, geofencing, and abused file-sharing platforms. Read the full breakdown and defense steps: 👈
0
2
8
@FortiGuardLabs
FortiGuard Labs
2 months
Cybercrime is evolving—your security needs to keep up the pace. 🔐 . ICYMI: Our 2025 Threat Landscape Report reveals how automation, #AI, and Crime-as-a-Service are accelerating attacks and shrinking the response window. Get the key insights:
1
5
14
@FortiGuardLabs
FortiGuard Labs
2 months
RT @Fortinet: Derek Manky, VP, Global Threat Intelligence, joined us at #RSAC today to discuss our 2025 Global Threat Landscape Report, rev….
0
4
0
@FortiGuardLabs
FortiGuard Labs
3 months
RT @happygeek: It's just another manic #Tuesday, oh wait. By me @Forbes: The rise and rise of infostealer malware. #kudos @FortiGuardLabs….
0
2
0
@FortiGuardLabs
FortiGuard Labs
3 months
Experts are calling it 'IngressNightmare' for a reason. ⚠️. Researchers discovered "IngressNightmare" (including CVE-2025-1974) in Ingress-NGINX, potentially allowing attackers to gain full control of your systems. This blog from FG Labs breaks down the vulnerabilities, shows our
0
2
9
@FortiGuardLabs
FortiGuard Labs
3 months
It's that time again! Our 2025 Global Threat Landscape Report is here, revealing a new reality—cybercrime has industrialized into a fast, automated, and scalable machine that exploits vulnerabilities before defenders can respond, demanding a shift to proactive exposure
0
3
12
@FortiGuardLabs
FortiGuard Labs
3 months
🚨 A newly disclosed RCE vulnerability in Kubernetes Ingress-NGINX, "IngressNightmare" is putting containerized environments at serious risk of exploit—making tools like #FortiCNAPP essential for robust security. 🔗 Full breakdown and mitigation steps:
0
1
6
@FortiGuardLabs
FortiGuard Labs
3 months
Deep dive into a new Formbook campaign! 🕵️‍♂️. We're tracking a sophisticated attack where malicious Word docs exploit CVE-2017-11882 to drop a fileless Formbook variant. Our first round of analysis covers the initial email, the exploit, the DLL downloader, and the process hollowing
0
3
13
@FortiGuardLabs
FortiGuard Labs
3 months
⚠️ Our #FortiGuardLabs' researchers have discovered #RustoBot—a Rust-based #malware targeting TOTOLINK devices via known command injection flaws. This variant marks a shift in tactics, exploiting CVEs for remote code execution. Learn more: 👈
0
2
10
@FortiGuardLabs
FortiGuard Labs
3 months
🔎 Our Annual 2024 Outbreak Alerts Report is here, and it's packed with critical insights!. Learn how #FortiGuardLabs processed and blocked trillions of attack attempts and billions of #malware deliveries across its global footprint. 📊
0
6
16
@FortiGuardLabs
FortiGuard Labs
3 months
🚨 Our #FortiGuardLabs team has uncovered a wave of malicious NPM packages. 👉 Published under the names tommyboy_h1 and tommyboy_h2, these packages use PayPal-themed names to appear legitimate while secretly exfiltrating sensitive system data.
0
3
9