FortiBleed: The IAB Campaign Has Harvested 110 Million Credentials from FortiGate Firewalls

Share:

The FortiBleed campaign is an ongoing, highly scaled cyber operation active since at least February 2026, primarily attributed to a financially motivated Russian Initial Access Broker (IAB). The operation blends automated mass scanning with targeted corporate profiling to compromise edge-networking devices and downstream corporate environments. Notably, its sophisticated targeting of a NATO-aligned defense contractor suggests potential secondary utility or collaboration with state-nexus elements.

Severity: High

Threat Overview

  • Target Scope: 430,000+ FortiGate firewalls
  • Credentials Identified: 110+ million
  • Unique Domains: 23,406
  • Operational Pipelines: 659+ credential-harvesting pipelines
  • Campaign Duration: Active since at least February 2026
  • Active Sniffing Targets: 19,000+ devices (80,553 identified)

Threat Actor Profile

  • Classification: Initial Access Broker (IAB) with financial motives
  • Likely Origin: Russian (Cyrillic comments in code, infrastructure choices)
  • Operational Maturity: Organized but not fully automated; relies on manual processes
  • Collaboration: May sell access to ransomware groups; evidence suggests possible state-sponsored group collaboration
  • High-Value Victims: NATO-aligned defense contractor confirmed

Five-Stage Attack Chain

Phase 1: Credential Sourcing & Reconnaissance

  • Sourcing: Pre-acquired multi-product credentials (creds.txt) are combined with 16 dictionaries (base0.txt to base15.txt) specifically curated for default/common FortiGate administrative account names.
  • Mass Discovery: Large-scale scanning via Masscan and passive data collection via Shodan_Recon.
  • Fingerprinting: Custom utilities like “FortiProbe” fast verify if a host is an active FortiGate device. RDNS-Scan and GeoSplit append reverse-DNS data and geolocate targets to isolate enterprise corporate entities. Secondary paths target RDP, SMB, and alternative VPN portals (Sophos, Citrix, RDWeb).

Phase 2: Pairing & Initial Access

  • Pairing: A custom utility (gen_rotator) pairs targets with credentials into a Cartesian product format required by automated validation tools.
  • Brute-Forcing: The actor deploys forticheck (a high-concurrency tool running up to 25,000 threads targeting administrative panels and SSL-VPN ports) and mpbrute2.bin (targeting administrative SSH interfaces) to achieve initial entry. Secondary targets include Synology DSM and MSSQL instances.

Phase 3: FortiGate Sniffer Deployment & Harvesting

  • FortigateSniffer authenticates to each compromised FortiGate via SSH and runs the FortiOS built-in command diagnose sniffer packet across all interfaces on 24 authentication ports. No malware is written to victim devices; only a native FortiOS diagnostic utility is invoked.

Phase 4: Credential Cracking & Lateral Movement

  • The PCAP Deep Analysis Toolkit parses captured traffic and produces Hashcat-ready files for NTLM, Kerberos, and RADIUS hashes; a Telegram bot (bot.py) orchestrates GPU cracking across a Hashtopolis cluster. Cracked credentials feed SMB validation, Active Directory enumeration via ad_full_audit.py, and Kerberoasting against domain controllers.

Phase 5: Collection & Exfiltration

  • Actors use custom scripts (backup_dfs.py / backup_dfs2.py) to recursively pull target files from internal network shares via SMB and stream them directly into remote SSH storage pipes. This design prevents writing stolen data to the local disk of the compromise pivot point.
  • Mass-produced automated shell scripts (curl_replay.sh) replay captured session cookies and tokens, allowing immediate, authenticated web access to internal corporate portals without triggering credential alerts.

Fortigatesniffer Capabilities

FortigateSniffer is a Golang-based credential-harvesting tool deployed in both Linux (fg_sniffer_linux_amd64) and Windows (fg_sniffer_windows_amd64.exe) builds, with a Russian-language operator interface. It runs six automated steps: load targets, inject sniffer via FortiOS CLI, convert output to .pcapng, extract credentials, generate cycle report, and repeat.

  • Multi-Protocol Capture: Captures authentication traffic via diagnose sniffer packet across 24 protocols.
  • Business-Hour Scheduling: Sniffer execution is restricted to 07:00–18:00 Moscow Time, maximising capture of live authentication sessions during business hours while reducing the likelihood of triggering out-of-hours SOC anomaly alerts.
  • GeoIP Filtering: A binary-search optimised GeoIP filter (ipgeo.csv) restricts sniffing to specific IP ranges, giving the operator geographic targeting control at the packet-capture level.
  • Credential Extraction: The PCAP Deep Analysis Toolkit (pcap_analyzer.py, 20+ modules) extracts cleartext credentials.
  • Session Cookie Replay: Captured HTTP session tokens are converted into host-specific curl_replay.sh scripts over 2,051 generated across compromised infrastructure enabling authenticated access to internal web applications without any additional exploitation.

Recommendations

  1. Check all FortiGate devices for unauthorised SSH logins and unexpected diagnose sniffer packet processes in diagnostic logs.
  2. Rotate all credentials tied to FortiGate admin interfaces, SSL-VPN portals, Active Directory, RADIUS, and MSSQL immediately.
  3. Remove FortiGate management interfaces from direct internet exposure; restrict SSH access to known management IP ranges only.
  4. Enable MFA on all FortiGate and VPN portals; audit active SSL-VPN sessions for anomalous or concurrent duplicate access.
  5. Block the IOCs at their respective controls
    https://www.virustotal.com/gui/collection/4bafc93211b1249c26b12dfd7ba8fe9069a143d2c6393aa25607452d35391c4f/iocs

Source:

  • https://socradar.io/wp-content/uploads/2026/06/Dismantling-FortiBleed.pdf
  • https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/
  • https://socradar.io/free-tools/fortibleed

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

×

7th August 2026

New Delhi, India

Know more
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert