logo

Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory

ID: 884317a1-8685-5dd1-a136-300296b8dd63

STIX ID: report--884317a1-8685-5dd1-a136-300296b8dd63

Feed Name: Arctic Wolf Blog

Threat Score
85/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

...
...

FortiBleed is a large-scale credential-harvesting and monetization campaign targeting internet-facing Fortinet FortiGate devices worldwide; recovered CyberStrike-branded tooling (harvester, FortiGate sniffer panel), cracking infrastructure (Hashcat/Hashtopolis and a Telegram orchestration bot), credential-cleaning and AD/SMB post-auth tooling convert captured configs and traffic into crackable hashes and validated VPN/SMB access for prioritized file-share collection and exfiltration — remediation requires immediate session invalidation, credential rotation, MFA, and restricting management interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.