FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN Gateways

FortiBleed: Russian-Speaking Credential-Harvesting Campaign (TL-2026-0895), also tracked as FortiBleed, is a high-severity tracked intrusion set, first published 2026-06-21. It is attributed to INC Ransom - G1032 (Russia) with medium confidence, affects Fortinet FortiGate / FortiOS, maps to 25 MITRE ATT&CK techniques (T1018, T1021, T1039), and is covered by 9 detection rules and 31 indicators of compromise.

Key facts for TL-2026-0895

Threat ID
TL-2026-0895
Also known as
FortiBleed
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-06-21
Last reviewed
2026-06-21
Attribution
INC Ransom - G1032
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
government, defense, financial, technology, telecommunications, managed-service-providers, critical-infrastructure
Target regions
Asia, North America, Europe, Middle East, Latin America, Global (194 countries)
Detection rules
9
Indicators of compromise
31

Malware and tooling in FortiBleed: Russian-Speaking Credential-Harvesting Campaign

Malware and tooling: Hashcat, Hashtopolis 0.14.3, Telegram bot tasking

FortiBleed is an active, large-scale credential-harvesting campaign in which Russian-speaking threat actors compromised internet-facing FortiGate firewalls and SSL VPN gateways across 194 countries by reusing leaked credentials, brute-forcing weak/MFA-less accounts, and offline-cracking legacy salted-SHA256 FortiOS hashes on a GPU cluster. Public reporting cites 73,932 affected firewall URLs (~50% of the internet-facing fleet) and 30,791 verified working credentials. This is not a new zero-day; it weaponizes weak password hygiene, absent MFA, and credentials exposed in prior Fortinet incidents (FG-IR-26-060, FG-IR-25-647).

How FortiBleed: Russian-Speaking Credential-Harvesting Campaign works

FortiBleed is a credential-harvesting and credential-validation campaign that targets internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways at global scale. Rather than exploiting a single new vulnerability, the operators chained together previously leaked Fortinet credentials, aggressive automated brute-force / credential-stuffing, and large-scale offline hash cracking against the legacy salted-SHA256 administrator-credential format used by older FortiOS builds.

Researchers (SOCRadar, Arctic Wolf, Recorded Future, CSO Online, SpyCloud, CloudSEK, Field Effect) describe an attacker-controlled open directory and orchestration stack left exposed on the internet. The operators ran a Hashtopolis 0.14.3 instance (reachable at 85.11.187.8:8443) coordinating a roughly 45-GPU cracking cluster (with ~36 Vast.ai rented GPU workers) using Hashcat to recover plaintext administrator and SSL VPN passwords from captured FortiOS config hashes (legacy salted-SHA256, PBKDF2, and krb5pa$18200 Kerberos formats). Telemetry attributed to the campaign includes roughly 1.16 billion credential attempts against 320,777 FortiGate targets and roughly 2.1 billion attempts against 163,650 MSSQL systems, indicating a broad automated credential-validation pipeline beyond Fortinet alone.

The operators maintained databases of validated credentials organized by country, sector, and organization revenue, and an exposed dataset attributed 21,632 entries (largely registration/realm metadata, with only a small fraction confirming real internal compromise — meaning headline breach counts are likely inflated). After authenticating to a FortiGate, attackers deployed passive network sniffers (logging to fg_capture.log) to harvest additional plaintext credentials transiting the perimeter device, created rogue administrator accounts (forticloud, fortiuser, fortinet-support, fortinet-tech-support), modified device configuration, and pivoted toward Active Directory / LDAP-integrated internal environments using enumeration (ad_enum.py, ad_full_audit.py), password spraying (spray_admin.sh, spray_da.py), and SMB/DFS collection-and-exfiltration tooling (backup_dfs.py, spider.py, smb_test.py). At least one working SSL VPN profile into a victim network (vpn5.conf) was found in the exposed directory. Confirmed victims span Japan, Taiwan, Vietnam, Iraq, and Türkiye, with reporting that a NATO defense contractor was targeted and documents allegedly exfiltrated; India, the United States, and Mexico held the largest concentrations of exposed credentials.

FortiOS builds prior to 7.2.11, 7.4.8, and 7.6.1 stored administrator credentials as salted SHA-256, which is feasible to crack offline; later builds (7.4/7.6/8.0 lines, beginning 7.2.11/7.4.8/7.6.1) introduce PBKDF2 hashing. Critically, legacy SHA-256 hashes persist in 'old-password' fields after an upgrade until each administrator logs in, extending the exposure window. Remediation requires terminating all admin/VPN sessions and rotating every credential, enforcing MFA, upgrading FortiOS, enabling 'set login-lockout-upon-weaker-encryption', auditing configurations for rogue accounts and unauthorized changes, restricting management-interface exposure, and reviewing logs and domain-controller telemetry for lateral-movement anomalies.

MITRE ATT&CK techniques used in TL-2026-0895

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1087 Account Discovery

Lateral Movement

T1021 Remote Services

Collection

T1039 Data from Network Shared Drive; T1074 Data Staged

Credential Access

T1040 Network Sniffing; T1110 Brute Force; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Defense Evasion

T1070 Indicator Removal

Command and Control

T1071 Application Layer Protocol; T1102 Web Service

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Persistence

T1098 Account Manipulation; T1136 Create Account

Resource Development

T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1588 Obtain Capabilities

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

Affected products and versions in FortiBleed: Russian-Speaking Credential-Harvesting Campaign

  • Fortinet — FortiGate / FortiOS
    Vulnerable versions: FortiOS prior to 7.2.11; FortiOS prior to 7.4.8; FortiOS prior to 7.6.1 (legacy salted-SHA256 administrator credential hashing)
    Fixed in: FortiOS 7.2.11+; FortiOS 7.4.8+; FortiOS 7.6.1+; 7.4 / 7.6 / 8.0 latest releases (PBKDF2 hashing)
  • Fortinet — FortiGate SSL VPN gateway
    Vulnerable versions: Internet-exposed SSL VPN on FortiOS builds without MFA and with legacy hashing
    Fixed in: PBKDF2-supporting FortiOS builds with MFA enforced

Remediation for FortiBleed: Russian-Speaking Credential-Harvesting Campaign

Patches

  • Upgrade FortiOS to a PBKDF2-supporting release (7.2.11+, 7.4.8+, 7.6.1+, or the 7.4 / 7.6 / 8.0 latest lines)

Immediate actions

  • Terminate all administrator and SSL VPN sessions and force-reset every administrator and VPN credential on internet-facing FortiGate devices
  • Audit FortiGate local admin accounts for rogue usernames (forticloud, fortiuser, fortinet-support, fortinet-tech-support) and remove any unrecognized accounts
  • Review device configuration for unauthorized changes, new admin profiles, and altered trusted-host/management-access settings
  • Block attacker infrastructure (85.11.187.8, 85.11.187.28, 193.8.187.2, 185.229.26.83, 213.169.49.142, 85.11.187.0/24) at the perimeter

Workarounds

  • Run 'set login-lockout-upon-weaker-encryption' to remove legacy weaker-encryption password settings and clear residual salted-SHA256 'old-password' hashes
  • Force every administrator to log in after upgrade so legacy SHA-256 hashes in 'old-password' fields are replaced with PBKDF2

Longer-term hardening

  • Enforce multi-factor authentication on all administrator and SSL VPN accounts
  • Restrict management and SSL VPN interfaces to trusted source hosts; remove direct internet exposure where possible
  • Audit Active Directory / LDAP integrations and domain controllers for enumeration, password spraying, and anomalous authentications
  • Establish known-good configuration baselines and continuously diff FortiGate configs against them

Weaknesses (CWE) in FortiBleed: Russian-Speaking Credential-Harvesting Campaign

CWE-916, CWE-522, CWE-307, CWE-798, CWE-1392, CWE-256

Timeline of FortiBleed: Russian-Speaking Credential-Harvesting Campaign

  • Earliest timestamped FortiGate credential-capture cycle observed (10:52 AM EDT); attackers also created a Cursor AI code editor account the same day.
  • HTTP activity observed on port 9999 of attacker infrastructure 85.11.187.8; Hashtopolis 0.14.3 coordination instance reachable at 85.11.187.8:8443.
  • Public disclosure of the FortiBleed dataset by researcher Volodymyr Diachenko; ~73,932 FortiGate firewall URLs reported exposed across 194 countries.
  • Follow-on intrusion activity observed June 14-15 across SSH, VNC, and RDP from attacker infrastructure.
  • Arctic Wolf and Field Effect publish FortiBleed bulletins; SOCRadar reports 30,791 verified working credentials and Russian-speaking attribution.
  • Recorded Future, CSO Online, SpyCloud, CloudSEK and TechTimes detail attacker open directory, 45-GPU Hashcat/Hashtopolis cluster, MSSQL targeting, and NATO defense contractor targeting.
  • Fortinet PSIRT publishes 'Analysis of Reported Credential Compromise of FortiGate Devices', referencing prior incidents FG-IR-26-060 and FG-IR-25-647 and PBKDF2 remediation guidance.
  • Cyber Security News publishes FortiBleed campaign report; threat tracked as TL-2026-0895.

Sources cited for FortiBleed: Russian-Speaking Credential-Harvesting Campaign

Threats related to FortiBleed: Russian-Speaking Credential-Harvesting Campaign

Detection coverage for TL-2026-0895

As of 2026-06-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0895 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-0895

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats