A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls as part of the FortiBleed credential-harvesting campaign, SOCRadar reports.
Discovered last week, the campaign has been ongoing since at least February, and was initially believed to be Fortinet-exclusive. But it is not.
In a fresh report (PDF), SOCRadar explains that FortiBleed is in fact a multi-vendor credential and access operation, likely mounted by a financially motivated threat actor.
“Attackers compromise exposed firewalls, harvest the authentication traffic and credentials passing through them, crack what they capture, and sell that access on,” the company told SecurityWeek.
Over 430,000 FortiGate firewalls worldwide are within the scope of the campaign and, of the 80,000 identified targets, more than 19,000 are still being actively sniffed, using a custom Golang tool dubbed FortigateSniffer.
The cybersecurity company’s investigation has uncovered hundreds of servers and more than 650 credential-harvesting pipelines used as part of the operation. Overall, it estimates that more than 110 million credentials were compromised.
“Because the firewall sits at the network edge, a compromise there can expose an organization’s entire identity layer — and the campaign reaches deep into supply chains, since MSPs and IT-services firms that manage Fortinet devices for others are squarely in the targeting,” SOCRadar says.
As part of the campaign, the threat actor uses tools such as Masscan and Shodan to identify vulnerable FortiGate appliances, and then compromises them in SSH brute-force attacks.
Next, they deploy network sniffers to capture cleartext credentials and password hashes, and then crack, validate, and use them for lateral movement against Active Directory domains and other services.
Ultimately, the attackers exfiltrate sensitive data from network shares and rely on stolen session cookies to establish persistent access to the compromised environments.
FortigateSniffer, the most important tool in the operation, abuses the legitimate FortiOS diagnostic command to passively capture authentication traffic across 24 protocols. The sniffer was likely built with the assistance of the AI-powered autonomous penetration testing agent CyberStrike.
The earliest artifacts associated with the campaign are from February and point to the scanning of Sophos SSL-VPN and RDWeb portals. MSSQL credentials, RDPs, Citrix SSL-VPNs, and RADIUS, NTLM, and Kerberos data are also within the campaign’s scope.
SOCRadar identified two credential sources maintained by the attackers. One combines data from previous leaks with purchased datasets, targeting multiple vendors, and the other includes 16 dictionaries specifically curated for FortiGate admin accounts.
“This large-scale data collection culminated on June 15 with the successful offline cracking of Kerberos hashes and the immediate, targeted exfiltration of DFS backup data from a NATO-aligned defense contractor,” SOCRadar notes.
The defense contractor’s compromise suggests the threat actor behind FortiBleed, likely a Russian-speaking IAB, may collaborate with Russian state-sponsored groups. However, it may also sell acquired access to ransomware gangs.
“The campaign shows a heavy focus on Small and Medium Businesses (SMBs) with fewer than 200 employees. The actor targets multiple sectors and regions, with notable emphasis on the United States and India,” SOCRadar says.
Related: Fortinet Responds to FortiBleed Campaign
Related: Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data
Related: Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
Related: The Zero-Knowledge Threat Actor and the End of Responsible Disclosure
