CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2111

As cited

Copy frozen at (site build).

vulnerabilities

BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA

Volexity discovered a zero-day credential disclosure vulnerability in Fortinet's FortiClient Windows VPN client in July 2024, exploited by the Chinese state-affiliated threat actor BrazenBamboo through its modular malware DEEPDATA. The vulnerability allows extraction of VPN credentials from the VPN client's process memory, and Fortinet published a public acknowledgement with patching guidance in December 2024. BrazenBamboo also operates related malware families including LIGHTSPY and DEEPPOST for information gathering and file exfiltration.

Why it matters: Organizations running FortiClient VPN on Windows are at immediate risk of credential theft if using unpatched versions; security teams must apply Fortinet's December 2024 patches and review logs for signs of DEEPDATA exploitation or credential extraction.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA

Chinese state-affiliated threat actor BrazenBamboo developed DEEPDATA, a modular post-exploitation tool that includes a plugin specifically designed to extract credentials from Fortinet FortiClient virtual private network (VPN) client process memory via a zero-day vulnerability. Volexity discovered the exploitation in July 2024 and disclosed it to Fortinet on July 18, 2024; Fortinet published a public acknowledgement and patching guidance on December 18, 2024. BrazenBamboo also developed two related malware families, LIGHTSPY and DEEPPOST, used for data collection and exfiltration.

Why it matters: Organizations using FortiClient VPN should prioritize patching to prevent credential theft and lateral movement by state-sponsored adversaries who have already weaponized this vulnerability in active campaigns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA

Chinese state-affiliated threat actor BrazenBamboo developed DEEPDATA, a modular post-exploitation tool that includes a plugin specifically designed to extract credentials from Fortinet FortiClient virtual private network (VPN) client process memory via a zero-day vulnerability. Volexity discovered the exploitation in July 2024 and disclosed it to Fortinet on July 18, 2024; Fortinet published a public acknowledgement and patching guidance on December 18, 2024. BrazenBamboo also developed two related malware families, LIGHTSPY and DEEPPOST, used for data collection and exfiltration.

Why it matters: Organizations using FortiClient VPN should prioritize patching to prevent credential theft and lateral movement by state-sponsored adversaries who have already weaponized this vulnerability in active campaigns.

VendorsMicrosoftFortinet
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary