UNC5820

Primary motivation
espionage
Sophistication
expert
Resource level
team
Actor type
unknown
Profile updated
2026-07-07 12:18:33

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

UNC5820 is a threat actor exploiting the CVE-2024-47575 vulnerability in Fortinet's FortiManager, allowing them to bypass authentication and execute arbitrary commands. They have been observed exfiltrating configuration data, user information, and FortiOS256-hashed passwords from managed FortiGate devices. While the actor has staged and exfiltrated sensitive data, there is currently no evidence of lateral movement or further compromise of additional environments. Mandiant has not determined whether UNC5820 is state-sponsored or identified its geographic location.

Exploited vulnerabilities

  • CVE-2024-47575 (vulnerability)

Reports & references

  • cloud.google.com — Fortimanager Zero Day Exploitation Cve 2024 47575 (report)

External references