FortiBleed Campaign: Custom FortigateSniffer Abuses FortiOS 'diagnose sniffer packet' to Harvest Credentials Across 24 Protocols — Threadlinqs Intelligence
As of 2026-06-22, FortiBleed Campaign: Custom FortigateSniffer Abuses FortiOS 'diagnose sniffer packet' to Harvest Credentials Across 24 Protocols is a critical-severity campaign threat attributed to FortiBleed operator (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-0907 · Severity: CRITICAL · Status: ACTIVE · Category: CAMPAIGN
Attribution: FortiBleed operator · Russia · FINANCIAL
FortiBleed is a large-scale Russian-speaking credential-harvesting operation, active since at least February 2026, that compromised hundreds of thousands of internet-facing FortiGate firewalls. After
FortiBleed is a credential-harvesting and initial-access-broker (IAB) operation publicly surfaced on 2026-06-13 by researcher Volodymyr 'Bob' Diachenko and corroborated by Kevin Beaumont, Hudson Rock, Huntress, SOCRadar, Recorded Future and others. The campaign does not rely on a zero-day; instead it monetizes weak/legacy FortiGate authentication. Operators first enumerate exposed FortiGate devices using reconnaissance tooling (Masscan, a custom Shodan_Recon utility, and a FortiProbe-fast binary), then gain administrative access through large-scale SSH brute-forcing (reportedly 16 curated wordlists), credential stuffing against SSL-VPN portals using previously leaked credentials, and the theft of exported FortiGate configuration files that contain hashed credentials.
Once a device is owned, the actor connects over SSH and runs a custom Golang implant, FortigateSniffer, which wraps the legitimate FortiOS troubleshooting command 'diagnose sniffer packet'. This 'living-off-the-land' approach captures plaintext and challenge/response authentication traffic for 24 protocols traversing the firewall — including Kerberos, RADIUS, NTLM, LDAP, SMB, RDP, WinRM, Microsoft SQL Server, MySQL, PostgreSQL, SMTP, IMAP, POP3, FTP and Telnet — without dropping conventional malware on the host. Captured packets are written to logs such as fg_capture.log. The sniffer is reported to run only between 07:00 and 18:00 Moscow Time to blend with legitimate business-hours traffic, a deliberate defense-evasion choice that also localizes the operators to a Russian/Eastern-European timezone (Cyrillic comments were observed in tooling).
Captured traffic is reconstructed into PCAP files by a component named SNIFTRAN and parsed by a Python 'PCAP Deep Analysis Toolkit' that extracts cleartext credentials, password hashes, Kerberos tickets, NTLM authentication material, and database/email credentials, emitting Hashcat-ready files. Hashes are cracked on a distributed GPU cluster (reported at 36-45 enterprise GPUs) orchestrated with Hashtopolis and Hashcat, using rented vast.ai capacity and Telegram bots for telemetry/coordination. Recovered valid credentials feed Active Directory enumeration (ad_enum.py, ad_full_audit.py), password spraying (spray_*.sh/py), and SMB/DFS data collection and exfiltration (backup_dfs.py, spider.py, smb_test.py), enabling deep network pivoting.
Reported scale is severe: 430,000+ FortiGate firewalls targeted; ~73,932-86,644 devices with confirmed valid admin/SSL-VPN credentials across 194 countries and 21,600+ domains; over 110 million credentials across 659+ harvesting pipelines; ~19,000 devices actively sniffed at time of reporting; and 1.16 billion brute-force attempts against 320,777 FortiGate targets plus 2.1 billion against 163,650 MSSQL systems. Victims skew toward SMBs (≈66% under 200 employees) but include government, telecom, financial, healthcare and manufacturing organizations, and an alleged NATO-aligned defense contractor compromise. Fortinet issued PSIRT guidance (FG-IR-26-060, related FG-IR-25-647) and CISA alerted on it; mitigation centers on credential reset, MFA, PBKDF2 password storage (FortiOS 7.4/7.6/8.0), disabling internet-exposed management, and hunting for unauthorized admin accounts (e.g., forticloud, fortiuser, fortinet-support).
Weaknesses (CWE)
CWE-1392, CWE-307, CWE-522, CWE-319, CWE-916
Target sectors: government, telecommunications, financial, healthcare, manufacturing, it-services, defense
Target regions: Global, India, United States, Taiwan, Europe, Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
CAMPAIGN, CRITICAL, threat intelligence, cybersecurity, T1595, T1590, T1596, T1583, T1587, T1588, T1190, T1133, T1078, T1059