logo

FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist

ID: 2245cfaa-ad74-56fb-99c4-67332923e579

STIX ID: report--2245cfaa-ad74-56fb-99c4-67332923e579

Feed Name: CosmicBytez Labs

Threat Score
92/100

Date Published: 2026-06-23

Date Updated: 2026-06-24

...
...

FortiBleed is a sophisticated, large-scale campaign that compromises Fortinet FortiGate devices to deploy a Golang-based sniffer (FortigateSniffer) which abuses the legitimate 'diagnose sniffer packet' command to capture credentials across ~24 authentication protocols. Captured data are reconstructed into PCAPs, parsed for cleartext credentials and hashes, and fed into a massive GPU cracking cluster; cracked credentials are recycled into automated lateral access scanners, producing over a billion credential attempts and sales of ~86,644 verified credentials. The campaign includes post-exploitation tunneling tools (Chisel, Neo-reGeorg), targeted data exfiltration (including a NATO-aligned contractor), and actionable IOCs and mitigation steps including rebuilds, credential rotation, and FortiOS upgrades.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.