PULSE NAME
FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch
WHITE AlienVault 2026-05-28 Modified: 2026-05-29
10
IOCs
LOW VOLUME
In May 2026, threat actors exploited CVE-2026-35616, an improper access control vulnerability in FortiClient Endpoint Management Server (EMS), to bypass API authentication and execute privileged requests without credentials. Attackers leveraged trusted endpoint management infrastructure to push malicious PowerShell scripts disguised as legitimate Fortinet patches across managed endpoints. The campaign deployed EKZ Infostealer, a credential-stealing tool targeting Chrome, Firefox, and other browser credentials. The stealer extracts passwords, cookies, and autofill data, staging results locally before exfiltration via HTTP to threat-actor-controlled infrastructure. Threat actors accessed systems through Tor exit nodes, modified VPN configurations to enable script execution, and used FortiClient's own management pathways to distribute payloads fleet-wide without requiring individual endpoint compromises.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
EKZ Infostealer
Indicators of Compromise (5 / 10 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 0da123adf9251957a4b850a3f6bd6a753dd4892be176a84a18450e899534cc5e 2026-05-28
FileHash-SHA256 2927bc31b4f8254c6b332fc03110a6373cad00ffa2ff9de427c26bb222017bb2 2026-05-28
FileHash-SHA256 2f25ea1b622abf3212141af932c2ec4cbd6b2b5903c2a531121f691227d98cff 2026-05-28
FileHash-SHA256 d91c00fad521e76efa89715cca89db487d5676f2c767c883482f9c8f82bd383a 2026-05-28
FileHash-SHA256 fd65051c61a904a304919c04a8c8633c001183ac73ac461cd4d9057946f02bf5 2026-05-28