More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
A Russian‐speaking broker known as FortiBleed has been running a large‐scale credential‐harvesting operation against more than 430,000 FortiGate firewalls since February 2026. Using Masscan, Shodan and custom tools like FortiProbe-fast and GeoSplit, the attackers identify vulnerable devices by country, brute-force admin panels with “forticheck,” then deploy a Golang sniffer—FortigateSniffer—via SSH. That sniffer taps into FortiOS’s diagnose sniffer packet command to capture cleartext and hashed credentials from 24 protocols, including TACACS+, Kerberos, LDAP, RDP and MS-SQL.
Once credentials pour in, the group cracks hashes with Hashmat and Hashtopolis, orchestrates cracking jobs through a Telegram bot called HASHBOT, and reuses valid logins for Active Directory reconnaissance, lateral movement and file‐share exfiltration. Between May 31 and June 15, they spun up 659 parallel pipelines, turning up 14.8 million RADIUS credentials, 924,000 NTLM hashes, 130,000 Kerberos hashes and 89 million MySQL tokens. They limit operations to 7 a.m.–6 p.m. Moscow Time, geo-fence targets and run five-hour cycles with 1,000 simultaneous threads, hitting a 90% validation rate in early runs.
FortiBleed isn’t confined to Fortinet gear. It’s part of a wider push that also brute-forces Synology NAS, Sophos firewalls, Citrix SSL-VPNs, RDWeb portals and MS-SQL servers. Attackers rank targets by economic value—SMBs under 200 employees, especially in the US and India, and IT service providers. A Brazilian firm, ZenoX, spotted repeated username:password pairs like adminin:ITAdmin@888 on thousands of devices—likely attacker-planted backdoors.
Amazon Threat Intelligence and Arctic Wolf reports suggest the group may have leaned on open-source AI tools such as CyberStrike and CyberStrikeAI for scanning and workflow automation. Fortinet says no zero-days are at play; weak passwords and missing MFA drive most breaches. The defining method is a feedback loop: initial access yields configuration artifacts and traffic that spawn fresh credentials and hashes, which in turn fuel deeper access across VPNs, SMB shares and Active Directory.
Questions about this article
No questions yet.