FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
ID: aa606406-78bb-5510-a025-96e2a403670a
STIX ID: report--aa606406-78bb-5510-a025-96e2a403670a
Feed Name: The Hacker News
The FortiBleed campaign is a financially motivated, Russian-speaking initial-access operation active since Feb 2026 that used mass scanning and brute-force to compromise FortiGate firewalls and other appliances; operators deployed a Golang tool (FortigateSniffer) leveraging FortiOS diagnostic packet sniffing to capture cleartext credentials and hashes across 24 protocols. The campaign reportedly impacted ~430,000 FortiGate devices, ran at least 659 credential-harvesting pipelines, and led to the collection of over 110 million credentials and authentication tokens; stolen data was cracked, validated, reused for Active Directory access and lateral movement, and exfiltrated, with pipelines organized by region, time-of-day geofencing, and automated orchestration (hash cracking via Hashmat/Hashtopolis and HASHBOT).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
