# FortiBleed operator

> As of 2026-06-24, FortiBleed operator is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, campaign. Also known as FortiBleed actor, FortigateSniffer operator. ATT&CK coverage spans 44 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1018 (Remote System Discovery), T1039 (Data from Network Shared Drive), T1040 (Network Sniffing).

- **Nation:** Russia
- **Tracked threats:** 3
- **Categories:** THREAT_INTEL, CAMPAIGN
- **Also known as:** FortiBleed actor, FortigateSniffer operator
- **As of:** 2026-06-24

## ATT&CK techniques observed

44 techniques observed across 3 of 3 tracked threats. Tactics: Credential Access (7), Resource Development (7), Lateral Movement (5), Reconnaissance (5), Collection (4), Command and Control (3).

- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1039](https://intel.threadlinqs.com/technique/T1039) Data from Network Shared Drive — Collection — observed in 3 of 3 tracked threats
- [T1040](https://intel.threadlinqs.com/technique/T1040) Network Sniffing — Credential Access — observed in 3 of 3 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 3 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 3 of 3 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 3 of 3 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 3 of 3 tracked threats
- [T1110](https://intel.threadlinqs.com/technique/T1110) Brute Force — Credential Access — observed in 3 of 3 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Initial Access — observed in 3 of 3 tracked threats
- [T1557](https://intel.threadlinqs.com/technique/T1557) Adversary-in-the-Middle — Credential Access — observed in 3 of 3 tracked threats
- [T1595](https://intel.threadlinqs.com/technique/T1595) Active Scanning — Reconnaissance — observed in 3 of 3 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 2 of 3 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats

## Tracked threats

- [FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet' (FortigateSniffer) to Harvest 110M+ Credentials From ~430,000 FortiGate Firewalls](https://intel.threadlinqs.com/threat/TL-2026-0927) — CRITICAL
- [FortiBleed: Russian Initial-Access-Broker Credential-Harvesting Campaign Weaponizing FortiGate Firewalls with the FortigateSniffer Tool](https://intel.threadlinqs.com/threat/TL-2026-0918) — HIGH
- [FortiBleed Campaign: Custom FortigateSniffer Abuses FortiOS 'diagnose sniffer packet' to Harvest Credentials Across 24 Protocols](https://intel.threadlinqs.com/threat/TL-2026-0907) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/FortiBleed%20operator
