FortiBleed Campaign Linked to INC and Lynx Ransomware Operations
ID: 66cba35f-fd62-57e8-b524-15d2abd9cfd3
STIX ID: report--66cba35f-fd62-57e8-b524-15d2abd9cfd3
Feed Name: GBHackers
Threat Score
Researchers uncovered that the FortiBleed campaign used a custom Golang tool to harvest FortiGate credentials from hundreds of thousands of devices, leading to administrative access in hundreds of cases and full compromises in dozens; evidence from exposed operator infrastructure links these stolen credentials directly to ransomware-as-a-service groups INC Ransom and Lynx, confirming that firewall credential theft is being integrated into ransomware deployment workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
