logo

FortiBleed campaign used custom FortiGate sniffer to steal credentials

ID: 34dc1f15-8cd2-56ce-ab46-04ad53ad65df

STIX ID: report--34dc1f15-8cd2-56ce-ab46-04ad53ad65df

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Lawrence Abrams

...
...

### Executive summary SOCRadar describes an active, large-scale campaign (FortiBleed) since at least February 2026 that targeted FortiGate firewalls (over 430,000 devices) by obtaining admin access via credential stuffing and brute-force, then abusing FortiOS's diagnose sniffer packet functionality with a Golang-based tool (FortigateSniffer) to capture authentication traffic; stolen credentials and hashes were extracted, converted to Hashcat-ready files and cracked on rented GPU clusters, resulting in a collection of many thousands of VPN and other authentication credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.