Attacker Breached 600 FortiGate Appliances in AI-Assisted Campaign: Amazon
好的,我现在需要帮用户总结一篇文章,控制在100字以内。首先,我得仔细阅读文章内容,抓住主要信息。 文章讲的是网络安全行业的一个新趋势:生成式AI工具让技术较低的威胁者也能发动大规模攻击。以前这类攻击需要经验丰富的黑客团队,现在AI降低了门槛。 亚马逊威胁情报部门报告了一个案例,一个俄语威胁者利用多个商业AI服务,入侵了600多台FortiGate设备,影响55个国家。攻击成功是因为暴露的管理端口和弱密码,而不是漏洞利用。 攻击者通过AI生成恶意软件、制定攻击计划,并在各个阶段使用AI工具。亚马逊研究人员发现攻击者的基础设施中有很多AI生成的代码和工具。 文章最后提到这种趋势预计会持续到2026年,组织需要加强安全措施来应对。 总结的时候要涵盖:AI如何改变威胁格局、具体案例、攻击手段、AI的作用以及未来的趋势。控制在100字以内,语言要简洁明了。 </think> 生成式AI工具正在改变网络安全威胁格局,使技术较低的攻击者能够发动大规模网络攻击。亚马逊威胁情报部门发现一名俄语威胁行为者利用多个商业可用的生成式AI服务,成功入侵了600多台FortiGate网络设备,并在全球范围内展开攻击活动。该攻击利用暴露的管理端口和弱凭证进行横向移动,并通过AI生成恶意软件和制定攻击计划。这一案例凸显了AI如何降低网络攻击的技术门槛,并使非专业威胁行为者能够实现更大规模的破坏活动。 2026-2-23 04:51:50 Author: securityboulevard.com(查看原文) 阅读量:19 收藏

The cybersecurity industry is getting another demonstration of how generative AI tools can allow lower-skilled threat actors to launch and run wide-ranging attacks that previously would have taken larger teams of more experienced hackers to pull off.

The latest example was reported by the Amazon Threat Intelligence unit, which said its researchers found a Russian-speaking threat actor using multiple commercially available GenAI services to compromise more than 600 of Fortinet’s FortiGate network appliances across more than 55 countries.

The campaign ran from January 11 to February 18, according to CJ Moses, CISO of Amazon Integrated Security.

“No exploitation of FortiGate vulnerabilities was observed – instead, this campaign succeeded by exploiting exposed management ports and weak credentials with single-factor authentication, fundamental security gaps that AI helped an unsophisticated actor exploit at scale,” Moses wrote in the report. “This activity is distinguished by the threat actor’s use of multiple commercial GenAI services to implement and scale well-known attack techniques throughout every phase of their operations, despite their limited technical capabilities.”

A Growing Trend

The Amazon investigation is the latest in a trend being seen of bad actors using AI tools not to only supplement their activities, but to generate malware and run the operation. AI vendor Anthropic reported in November 2025 about a China-linked group using its Claude Code model to run an espionage campaign, while Check Point in January wrote about a single actor who used an AI model to generate an advanced malware called “VoidLink.”

Darktrace researchers earlier this month caught a malware sample in its honeypot network that they said was entirely generated by AI. Now Amazon is weighing in.

“This investigation highlights how commercial AI services can lower the technical barrier to entry for offensive cyber capabilities,” Moses wrote. “The threat actor in this campaign is not known to be associated with any advanced persistent threat group with state-sponsored resources. They are likely a financially motivated individual or small group who, through AI augmentation, achieved an operational scale that would have previously required a significantly larger and more skilled team.”

Compromised AD, Stole Credentials

However, Amazon researchers found the threat actor compromised the Microsoft Active Directory (AD) environment of multiple organizations, stole credential databases, and targeted backup infrastructure, which often is an early step in a ransomware campaign.

“Notably, when this actor encountered hardened environments or more sophisticated defensive measures, they simply moved on to softer targets rather than persisting, underscoring that their advantage lies in AI-augmented efficiency and scale, not in deeper technical skill,” he wrote.

Amazon researchers identified publicly accessible infrastructure that was hosting malicious tools associated with the campaign and noted that the attacker had placed other operational files on the same infrastructure, including AI-generated attack plans, source code for custom tools, and victim configurations.

“This inadequate operational security provided comprehensive visibility into the threat actor’s methodologies and the specific ways they leverage AI throughout their operations,” he wrote. “It’s like an AI-powered assembly line for cybercrime, helping less skilled workers produce at scale.”

Accessing FortiGate Appliances

By compromising the FortiGate appliances – which often act as next-generation firewalls – the threat actor pulled full device configurations that included credentials, network information, and device configuration. They took the credentials to connect to the internal networks of victims, compromise their AD environments, harvest other credentials, and try to access backup infrastructure.

The attacker gained initial access through internet-facing FortiGate interfaces, scanning across ports 443, 8443, 10443, and 4443 and then used reused credentials in authentication attempts. The devices were located in South and Southeast Asia, Latin American, West Africa, Northern Europe, and the Caribbean, as well as other regions.

After gaining access to the networks, the threat actor deployed different versions of a custom reconnaissance tool written in Go or Python and showing indications that it was developed with the help of AI, including comments that simply restate function names, simplistic architecture with a focus on formatting over functionality, and JSON parsing through string matching instead of deserialization.

“While functional for the threat actor’s specific use case, the tooling lacks robustness and fails under edge cases – characteristics typical of AI-generated code used without significant refinement,” Moses wrote.

Moving Laterally

Once in the networks, the attacker moved laterally and targeted Veeam Backup and Replication servers with credential-extracting tools and PowerShell scripts, and exploitation attempts against known Veeam flaws.

Moses wrote that the bad actors used at least two large language model (LLM) vendors to generate attack methodologies, including step-by-step exploitation instructions, expected success rates, time estimates, and prioritized task trees. They also used multiple AI services in complementary roles, including as the primary tool developer, attack planner, and operational assistant, and as a supplementary attack planner for when they needed help pivoting in a compromised network.

The infrastructure also included scripts in multiple programming languages, implying they were created by AI. Among the indicators were configuration parsers, credential extraction tools, VPN connection automation, mass scanning orchestration, and result aggregation dashboards.

‘Expect This Trend to Continue in 2026’

“The volume and variety of custom tooling would typically indicate a well-resourced development team. Instead, a single actor or very small group generated this entire toolkit through AI-assisted development,” Moses wrote. “As we expect this trend to continue in 2026, organizations should anticipate that AI-augmented threat activity will continue to grow in volume from both skilled and unskilled adversaries.”

Organizations need to ensure they continue patch management for perimeter devices, credential protections, network segmentation, and strong detection for post-exploitation indicators, he wrote.

Recent Articles By Author


文章来源: https://securityboulevard.com/2026/02/attacker-breached-600-fortigate-appliances-in-ai-assisted-campaign-amazon/
如有侵权请联系:admin#unsafe.sh