Hackers Using FortigateSniffer Tool That Turns Compromised Firewalls Into Password Collectors
ID: d91a6227-abb6-5c47-91eb-d854e377e2fb
STIX ID: report--d91a6227-abb6-5c47-91eb-d854e377e2fb
Feed Name: cybersecurityNews.com
SOCRadar reports a large-scale, financially motivated campaign named “FortiBleed” in which attackers deployed a custom Golang tool (FortigateSniffer) on FortiGate firewalls worldwide to passively sniff and exfiltrate credentials across dozens of protocols; the operation harvested an estimated 110+ million credentials from over 430,000 appliances, used sophisticated targeting, evasion and cracking infrastructure, and includes confirmed targeted exfiltration from a NATO-aligned defense contractor, with multiple IoCs and active infrastructure identified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
