The attacker appears to have targeted FortiGate devices whose management ports were exposed online, used weak passwords, and lacked MFA.