FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch
May 29, 2026, 10:39 a.m.
Description
In May 2026, threat actors exploited CVE-2026-35616, an improper access control vulnerability in FortiClient Endpoint Management Server (EMS), to bypass API authentication and execute privileged requests without credentials. Attackers leveraged trusted endpoint management infrastructure to push malicious PowerShell scripts disguised as legitimate Fortinet patches across managed endpoints. The campaign deployed EKZ Infostealer, a credential-stealing tool targeting Chrome, Firefox, and other browser credentials. The stealer extracts passwords, cookies, and autofill data, staging results locally before exfiltration via HTTP to threat-actor-controlled infrastructure. Threat actors accessed systems through Tor exit nodes, modified VPN configurations to enable script execution, and used FortiClient's own management pathways to distribute payloads fleet-wide without requiring individual endpoint compromises.
Tags
Date
- Created: May 28, 2026, 3:18 p.m.
- Published: May 28, 2026, 3:18 p.m.
- Modified: May 29, 2026, 10:39 a.m.
Indicators
- 2927bc31b4f8254c6b332fc03110a6373cad00ffa2ff9de427c26bb222017bb2
- d91c00fad521e76efa89715cca89db487d5676f2c767c883482f9c8f82bd383a
- fd65051c61a904a304919c04a8c8633c001183ac73ac461cd4d9057946f02bf5
- 2f25ea1b622abf3212141af932c2ec4cbd6b2b5903c2a531121f691227d98cff
- 0da123adf9251957a4b850a3f6bd6a753dd4892be176a84a18450e899534cc5e
Attack Patterns
- EKZ Infostealer