Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices
2026-06-17T14:51:50Z•7167f40b0c05d35b873b446b4d96175cd976497e7ca2f0804c3c8789fdd708ce
android-trojancheck-point-vpncompromised-devicescopilotcredential-harvestingcredential-stuffingfileless-malwarefortinethadeshttp2-dosironwormivantikernel-driver-abusemiasmamicrosoft-exchangeoracle-zero-daypatch-managementphantom-stealerphishingprompt-injectionrokarollasprysockssupply-chain-wormwinrarzero-day-exploitation
What happened
A series of high-impact incidents reported by DarkReading shows a widespread credential-harvesting campaign that has compromised >30,000 Fortinet devices across ~200 countries and produced a large corpus of working credentials. Multiple active threats and rapid exploitations are highlighted: fileless “Phantom” stealer targeting browser credentials; a SprySOCKS Windows variant abusing kernel drivers; the Rokarolla Android trojan achieving full device control and persistence; supply-chain worms (Miasma, IronWorm, Hades) targeting developer ecosystems; and high-profile vulnerability exploitation,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 7167f40b0c05d35b873b446b4d96175cd976497e7ca2f0804c3c8789fdd708ce
- Enrichment time
- 2026-06-17T14:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.