Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-06

FortiBleed operator

Also known as:FortiBleed actorFortigateSniffer operator

As of 2026-06-24, FortiBleed operator is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, campaign. Also known as FortiBleed actor, FortigateSniffer operator. ATT&CK coverage spans 44 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1018 (Remote System Discovery), T1039 (Data from Network Shared Drive), T1040 (Network Sniffing).

Tracked threats
32 critical · 1 high
First seen
2026-06-22
Last seen
2026-06-24
ATT&CK techniques
44across 3 of 3 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 3 tracked threat(s) · Categories: THREAT_INTEL, CAMPAIGN

Activity timeline

FortiBleed operator appears in 3 tracked threats between and .

ATT&CK techniques observed

44 techniques observed across 3 of 3 tracked threats · Credential Access (7), Resource Development (7), Lateral Movement (5), Reconnaissance (5), Collection (4), Command and Control (3)
  • T1018 Remote System Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1039 Data from Network Shared Drive — Collectionobserved in 3 of 3 tracked threats
  • T1040 Network Sniffing — Credential Accessobserved in 3 of 3 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 3 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 3 of 3 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 3 of 3 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1102 Web Service — Command and Controlobserved in 3 of 3 tracked threats
  • T1110 Brute Force — Credential Accessobserved in 3 of 3 tracked threats
  • T1133 External Remote Services — Initial Accessobserved in 3 of 3 tracked threats
  • T1557 Adversary-in-the-Middle — Credential Accessobserved in 3 of 3 tracked threats
  • T1595 Active Scanning — Reconnaissanceobserved in 3 of 3 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 2 of 3 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats

Tracked threats