The images in this article were generated with artificial intelligence. How we publish
In recent weeks an active campaign has been detected that explores the vulnerability of authentication omission CVE-2026-35616 in FortiClient Enterprise Management Server (EMS) to distribute a infostealer called EKZ disguised as a legitimate update of Fortinet. The vector combines an access control failure in the EMS API with the administrative capacity of the product to impose configuration changes and run scripts on managed endpoints, transforming a central management infrastructure into a malware distribution channel.
The attack scheme, described by Arctic Wolf researchers, begins with specially manipulated requests against the EMS API that do not require valid authentication, allowing attackers to create or modify remote access profiles and VPN policies. Once an endpoint sets an IPsec tunnel towards a FortiGate, legitimate components such as fortitra.exe are induced to run scripts by platform commands, and those scripts invoke PowerShell to download a binary that is presented as a Fortinet patch. The EKZ executable steals credentials, cards, cookies and other data from Chromium and Firefox browsers, and exfilters them by HTTP to attacker-controlled servers.

Two important technical elements that should turn on alarms in response teams are the appearance in the chain logs "Certificate not found in request header" followed by entries indicating certificate update (e.g. "Certificate user: fortinet-ca2... successfully updated") and unexpected execution of scripts by FortiClient processes. These signals, together with unauthorized changes in remote access profiles or new administrative accounts, are clear indicators of commitment of the EMS.
The implications are serious because the campaign exploits a piece of software with privileges over hundreds or thousands of endpoints: when the management console is compromised, the attacker does not need to compromise each team one by one. In addition, the removal of cookies and session data allows to avoid protections such as MFA in many services, and the cleaning of local artifacts makes it difficult to detect post-commitment. Response groups like The Shadowserver warned about EMS instances exposed on the Internet, and government agencies (CISA) forced urgent mitigation actions for federal environments.
If your organization uses FortiClient EMS, the first and most urgent action is apply the corrections and hotfixes published by Fortinet for the affected versions (Fortinet published emergency patches for the affected lines, and it is essential to follow its official guidelines). Even if it is not possible to park immediately, it is recommended to isolate the EMS consoles from the public network, restrict administrative access from reliable PIs, and block access to the management API from unmanaged networks.
In detection and response, give priority to the review of log in search of the above-mentioned signals, audit recent changes in Remote Access Profiles and VPN policies, and seek administrative activity from unusual origins (VPS PIs, Tor proxies, etc.). Monitor processes in endpoints managed to detect cmd.exe or PowerShell launches initiated by fortitray.exe and enable detailed PowerShell (script block logging) and EDR telemetry to capture base64 commands and remote downloads. If there are signs of commitment, disconnect and foresee the affected endpoints, rote credentials and cookies exposed, and consider revoking certificates that may have been handled.

In addition to reactive measures, strengthen preventive controls: apply network segmentation to separate management consoles, limit administrative privileges through minimum privilege principles, implement white lists of applications where feasible and use anomalies detection for automated configuration changes. To protect the distribution chain, value signatures and update integrity mechanisms and treat with particular mistrust updates that do not come directly from official Fortinet channels.
For technical details and additional detection guide see the Arctic Wolf analysis and public information on vulnerability in official sources: Arctic Wolf report and the vulnerability sheet in the NVD ( CVE-2026-35616). For Fortinet's corrections and notices, see your PSIRT portal and product notifications at Fortinet PSIRT.
In short, this campaign is a reminder that remote management platforms are high-value objectives: quickly patching, monitoring configurations and ensuring administration channels are critical measures to prevent a tool designed to protect the network from becoming its attack vector. If you suspect that your EMS has been compromised, prioritize the isolation and forensic investigation and contact your provider and response services to coordinate mitigation.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...