Russian Initial Access Broker Behind FortiBleed Campaign
ID: 51483d72-31af-5bdf-8f3a-32e6e7da8a29
STIX ID: report--51483d72-31af-5bdf-8f3a-32e6e7da8a29
Feed Name: CosmicBytez Labs
SOCRadar and researchers uncovered 'FortiBleed', an ongoing large-scale credential-harvesting campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPNs that has collected 86,644 verified credentials and 110M+ captured items across ~194 countries; attackers use mass scanning and brute-force/credential-stuffing to deploy a Golang 'FortigateSniffer' to capture cleartext credentials, then run a GPU-backed cracking pipeline, perform lateral movement and exfiltration, and may collaborate with or sell access to state-aligned groups—organizations are advised to rotate credentials, enable MFA, remove public management interfaces, upgrade FortiOS to versions with PBKDF2 hashing, and engage incident response if indicators are found.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
