Hackers exploit FortiClient EMS flaw to push infostealer malware
Hackers are abusing a FortiClient EMS auth bypass to run scripts that install EKZ, a credential-stealing malware, on endpoints.
Intelligence analysis by GPT-5.4 Mini

Attackers are using CVE-2026-35616 in FortiClient EMS to make managed endpoints run malicious update scripts. Arctic Wolf says the campaign drops EKZ, an infostealer that steals browser data and sends it to attacker infrastructure.
A company’s security tool was supposed to help computers stay safe. Hackers found a weak spot and used it like a fake key to make the tool run their own code.
That code quietly installed a thief program called EKZ. It looked for saved passwords, cookies, and other private details in web browsers, then sent the stolen data to the hackers.
It is like a burglar sneaking in by wearing a delivery uniform and convincing the front desk to open the door. Security teams now need to watch for strange log messages and sudden changes in the tool’s settings.
Analysis
What happened
Hackers are exploiting CVE-2026-35616 in FortiClient Enterprise Management Server, an authentication bypass and access-control flaw that lets unauthenticated attackers execute commands through crafted requests. Fortinet said in early April that the bug was being exploited and released emergency hotfixes for versions 7.4.5 and 7.4.6.
How the attack works
According to Arctic Wolf, the attack starts by abusing endpoint APIs to perform administrative actions without logging in. The attacker then changes EMS configuration and VPN policies so that FortiClient-managed workflows launch malicious scripts. After endpoints establish an IPsec tunnel to a FortiGate firewall, the legitimate fortitray.exe process starts batch files through Command Prompt. Those scripts run base64-encoded PowerShell that downloads malware disguised as a Fortinet patch, executes it quietly, and sends stolen data to an attacker-controlled VPS over HTTP.
What EKZ does
The payload, tracked as EKZ Infostealer, is a credential stealer with standard browser-theft features. Arctic Wolf says it targets Chromium-based browsers and Firefox, extracts stored data into text files, and bypasses encrypted password protections. It steals credentials, credit card details, addresses, phone numbers, and cookies that can be used to access accounts protected by multi-factor authentication.
What defenders should look for
Arctic Wolf says one clue is the log line “Certificate not found in request header.” In testing, that was followed seconds later by a certificate update message. The researchers recommend watching for certificate-authentication anomalies, unexpected changes to Remote Access Profile settings, new accounts, unfamiliar login origins such as Tor or VPS IPs, and other suspicious administrative changes.
Key points
- Hackers are exploiting CVE-2026-35616 in FortiClient EMS to run commands without authentication.
- Arctic Wolf says the attack chain uses FortiClient-managed VPN scripting to launch malicious PowerShell.
- The payload is EKZ Infostealer, which steals browser data, credentials, cookies, and payment details.
- Fortinet issued emergency hotfixes in April for versions 7.4.5 and 7.4.6 after confirming exploitation.
- Defenders are told to watch for certificate-authentication errors, remote profile changes, and suspicious admin activity.



