Malware Analysis Report: UMBRELLA STAND - Malware targeting Fortinet devices

June 24, 2025, 2:32 p.m.

Description

UMBRELLA STAND is a sophisticated malware targeting FortiGate 100D series firewalls produced by Fortinet. It contains remote shell execution functionality, configurable beacon frequency, and AES-encrypted C2 communications. The malware uses fake TLS on port 443 to beacon to its C2 server and has the ability to run shell commands. It employs various defense evasion techniques such as hidden folders, generic filenames, and string encryption. UMBRELLA STAND also has persistence mechanisms through reboot hooking and ldpreload. Associated tooling includes BusyBox, nbtscan, tcpdump, and openLDAP. The malware demonstrates operational security considerations and shares similarities with previously reported COATHANGER malware.

Date

  • Created: June 23, 2025, 11:34 a.m.
  • Published: June 23, 2025, 11:34 a.m.
  • Modified: June 24, 2025, 2:32 p.m.

Indicators

  • d1d5f502e2039b20269b562bbc1e5622a73bbecad54cb25ae5eaa7a91504e70e
  • d3b88b7f640e478d8d875e12b4561e8c794909e4954aebbc6fd1f5e79f381648
  • a64b41e98e3e1066f41fbff5d4f99f6d34b792d35fe2be7e5d9fa8f3f8b93739
  • 8bacd5df99476328321a7e8e2fc0124c20f7a7ebf3e8f151c050387038515b70
  • 881998c9864d2c7fe35f9b8071dbcf84386cb15da77e6f6a086cf605a4dd7823
  • 6a3abc19f324a475d4ce01fcc69797fc90e1a47970ed90e9cb01f540f3000b4e
  • 65f1e17f7fa2e2fd9c57265f390484a7428c192f59ee41fc7c0d8386ea3b811a
  • 591d60c1d356da827a26f4141fa431d3663af91746d5371014695b1c89bac2b2
  • 38801caae26916367dd6cf6e8c55e50ed62526fe242cd0343dfe80a70564c28a
  • 190293440fce95f45eb8bf5d40334b41dd68c79578d06fe9b34670298daea7f3
  • 89.44.194.32

Attack Patterns

  • SHOE RACK
  • UMBRELLA STAND

Additional Informations

  • Defense
  • Government