Activity timeline
FortiBleed operator appears in 3 tracked threats between and .
ATT&CK techniques observed
- T1018 Remote System Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1039 Data from Network Shared Drive — Collectionobserved in 3 of 3 tracked threats
- T1040 Network Sniffing — Credential Accessobserved in 3 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 3 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 3 of 3 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 3 of 3 tracked threats
- T1087 Account Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1102 Web Service — Command and Controlobserved in 3 of 3 tracked threats
- T1110 Brute Force — Credential Accessobserved in 3 of 3 tracked threats
- T1133 External Remote Services — Initial Accessobserved in 3 of 3 tracked threats
- T1557 Adversary-in-the-Middle — Credential Accessobserved in 3 of 3 tracked threats
- T1595 Active Scanning — Reconnaissanceobserved in 3 of 3 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 2 of 3 tracked threats
- T1046 Network Service Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
Tracked threats
- FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet' (FortigateSniffer) to Harvest 110M+ Credentials From ~430,000 FortiGate FirewallsCRITICAL
- FortiBleed: Russian Initial-Access-Broker Credential-Harvesting Campaign Weaponizing FortiGate Firewalls with the FortigateSniffer ToolHIGH
- FortiBleed Campaign: Custom FortigateSniffer Abuses FortiOS 'diagnose sniffer packet' to Harvest Credentials Across 24 ProtocolsCRITICAL