FortiBleed campaign used custom FortiGate sniffer to steal credentials
ID: 34dc1f15-8cd2-56ce-ab46-04ad53ad65df
STIX ID: report--34dc1f15-8cd2-56ce-ab46-04ad53ad65df
Feed Name: Bleeping Computer
### Executive summary SOCRadar describes an active, large-scale campaign (FortiBleed) since at least February 2026 that targeted FortiGate firewalls (over 430,000 devices) by obtaining admin access via credential stuffing and brute-force, then abusing FortiOS's diagnose sniffer packet functionality with a Golang-based tool (FortigateSniffer) to capture authentication traffic; stolen credentials and hashes were extracted, converted to Hashcat-ready files and cracked on rented GPU clusters, resulting in a collection of many thousands of VPN and other authentication credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
