FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN Gateways — Threadlinqs Intelligence
As of 2026-07-02, FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN Gateways is a high-severity threat intel threat attributed to INC Ransom (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-0895 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: INC Ransom · Russia · FINANCIAL
FortiBleed is an active, large-scale credential-harvesting campaign in which Russian-speaking threat actors compromised internet-facing FortiGate firewalls and SSL VPN gateways across 194 countries by
FortiBleed is a credential-harvesting and credential-validation campaign that targets internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways at global scale. Rather than exploiting a single new vulnerability, the operators chained together previously leaked Fortinet credentials, aggressive automated brute-force / credential-stuffing, and large-scale offline hash cracking against the legacy salted-SHA256 administrator-credential format used by older FortiOS builds.
Researchers (SOCRadar, Arctic Wolf, Recorded Future, CSO Online, SpyCloud, CloudSEK, Field Effect) describe an attacker-controlled open directory and orchestration stack left exposed on the internet. The operators ran a Hashtopolis 0.14.3 instance (reachable at 85.11.187.8:8443) coordinating a roughly 45-GPU cracking cluster (with ~36 Vast.ai rented GPU workers) using Hashcat to recover plaintext administrator and SSL VPN passwords from captured FortiOS config hashes (legacy salted-SHA256, PBKDF2, and krb5pa$18200 Kerberos formats). Telemetry attributed to the campaign includes roughly 1.16 billion credential attempts against 320,777 FortiGate targets and roughly 2.1 billion attempts against 163,650 MSSQL systems, indicating a broad automated credential-validation pipeline beyond Fortinet alone.
The operators maintained databases of validated credentials organized by country, sector, and organization revenue, and an exposed dataset attributed 21,632 entries (largely registration/realm metadata, with only a small fraction confirming real internal compromise — meaning headline breach counts are likely inflated). After authenticating to a FortiGate, attackers deployed passive network sniffers (logging to fg_capture.log) to harvest additional plaintext credentials transiting the perimeter device, created rogue administrator accounts (forticloud, fortiuser, fortinet-support, fortinet-tech-support), modified device configuration, and pivoted toward Active Directory / LDAP-integrated internal environments using enumeration (ad_enum.py, ad_full_audit.py), password spraying (spray_admin.sh, spray_da.py), and SMB/DFS collection-and-exfiltration tooling (backup_dfs.py, spider.py, smb_test.py). At least one working SSL VPN profile into a victim network (vpn5.conf) was found in the exposed directory. Confirmed victims span Japan, Taiwan, Vietnam, Iraq, and Türkiye, with reporting that a NATO defense contractor was targeted and documents allegedly exfiltrated; India, the United States, and Mexico held the largest concentrations of exposed credentials.
FortiOS builds prior to 7.2.11, 7.4.8, and 7.6.1 stored administrator credentials as salted SHA-256, which is feasible to crack offline; later builds (7.4/7.6/8.0 lines, beginning 7.2.11/7.4.8/7.6.1) introduce PBKDF2 hashing. Critically, legacy SHA-256 hashes persist in 'old-password' fields after an upgrade until each administrator logs in, extending the exposure window. Remediation requires terminating all admin/VPN sessions and rotating every credential, enforcing MFA, upgrading FortiOS, enabling 'set login-lockout-upon-weaker-encryption', auditing configurations for rogue accounts and unauthorized changes, restricting management-interface exposure, and reviewing logs and domain-controller telemetry for lateral-movement anomalies.
Weaknesses (CWE)
CWE-916, CWE-522, CWE-307, CWE-798, CWE-1392, CWE-256
Target sectors: government, defense, financial, technology, telecommunications, managed-service-providers, critical-infrastructure
Target regions: Asia, North America, Europe, Middle East, Latin America, Global (194 countries)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1595, T1590, T1583, T1588, T1586, T1078, T1133, T1190, T1110, T1110