logo

Hackers Using FortigateSniffer Tool That Turns Compromised Firewalls Into Password Collectors

ID: d91a6227-abb6-5c47-91eb-d854e377e2fb

STIX ID: report--d91a6227-abb6-5c47-91eb-d854e377e2fb

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Guru Baran

...
...

SOCRadar reports a large-scale, financially motivated campaign named “FortiBleed” in which attackers deployed a custom Golang tool (FortigateSniffer) on FortiGate firewalls worldwide to passively sniff and exfiltrate credentials across dozens of protocols; the operation harvested an estimated 110+ million credentials from over 430,000 appliances, used sophisticated targeting, evasion and cracking infrastructure, and includes confirmed targeted exfiltration from a NATO-aligned defense contractor, with multiple IoCs and active infrastructure identified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.