Attackers exploit FortiClient EMS to push previously undetected EKZ infostealer malware through trusted administrative scripts.