FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
ID: 86b8a26f-3d75-52ac-8f1f-0a55400d8d96
STIX ID: report--86b8a26f-3d75-52ac-8f1f-0a55400d8d96
Feed Name: Recorded Future Blog
## Executive Summary A dataset called "FortiBleed" allegedly exposes valid administrative and SSL VPN credentials for ~73,932 FortiGate firewall URLs across 194 countries; researchers validated sampled credentials and linked the campaign to a Russian-speaking threat group that targeted government, critical infrastructure, and multinational organizations. Attackers reportedly harvested exported FortiGate configs, intercepted SSL VPN hashes, used a 45-GPU cracking cluster (Hashcat/Hashtopolis) to recover plaintext credentials, and used those credentials for Active Directory access and follow-on intrusions; Recorded Future identified infrastructure artifacts and an associated IP (85.11.187.8). The report urges immediate credential rotation, MFA enforcement, log review, interface exposure reduction, patching, and internal hunt for compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
