FortiBleed: Russian Initial-Access-Broker Credential-Harvesting Campaign Weaponizing FortiGate Firewalls with the FortigateSniffer Tool

FortiBleed: Russian Initial-Access-Broker (TL-2026-0918), also tracked as FortiBleed, is a high-severity tracked intrusion set, first published 2026-06-23. It is attributed to FortiBleed operator (Russia) with medium confidence, affects Fortinet FortiGate (FortiOS) firewall / SSL VPN gateway, maps to 22 MITRE ATT&CK techniques (T1018, T1021, T1039), and is covered by 9 detection rules and 28 indicators of compromise.

Key facts for TL-2026-0918

Threat ID
TL-2026-0918
Also known as
FortiBleed, FortigateSniffer campaign
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-06-23
Last reviewed
2026-06-23
Attribution
FortiBleed operator
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
government, defense, financial, healthcare, technology, telecommunications, managed-service-providers
Target regions
Global, North America, Europe, Asia, Middle East
Detection rules
9
Indicators of compromise
28

Malware and tooling in FortiBleed: Russian Initial-Access-Broker

Malware and tooling: CyberStrike, FortigateSniffer, Hashcat, Hashtopolis, Impacket - S0357, Telegram Hashcat Bot (NetNTLMv2 Cracker v10)

FortiBleed is an active, financially motivated credential-harvesting operation in which a Russian-aligned initial access broker turned internet-exposed FortiGate firewalls and SSL VPN gateways into passive surveillance points. A custom Go tool (FortigateSniffer / harvest_orig) abuses the FortiOS 'diagnose sniffer packet' command to capture authentication traffic across 24 protocols; captured hashes are cracked on a Vast.ai-rented GPU cluster managed via Hashtopolis/Hashcat and orchestrated through a Telegram bot.

How FortiBleed: Russian Initial-Access-Broker works

FortiBleed is a large-scale, ongoing credential-compromise campaign against Fortinet FortiGate firewalls and SSL VPN gateways, first named publicly in mid-June 2026 after an attacker staging server was found exposed. The operator profile is consistent with a Russian-origin initial access broker (IAB) selling access to ransomware affiliates: tooling carries Cyrillic-language comments and the harvesting component only runs between 07:00 and 18:00 Moscow Time to blend with business-hours traffic.

Initial access is achieved by mass-scanning the internet (Masscan / custom Shodan_Recon / FortiProbe-fast) for FortiGate devices with exposed management interfaces, then authenticating with credentials sourced from prior Fortinet leaks and infostealer logs, or recovered by brute-force and GPU hash-cracking. Wordlists are curated for FortiGate admin naming conventions. Once a device is reached, the actor abuses the legitimate FortiOS diagnostic capability 'diagnose sniffer packet' via a Golang harvester (filename harvest_orig, a ~4.3 MB static ELF; a Windows/amd64 scanner variant also exists) to passively intercept authentication material for 24 protocols including NTLMv1/NTLMv2, Kerberos RC4/AES pre-auth, AS-REP, Kerberoast, HTTP Basic/Form/JSON, LDAP, MSSQL, MySQL, PostgreSQL, RADIUS, SNMP, RDP, WinRM, SSH, FTP, Telnet, SMTP, IMAP, POP3, and cleartext tokens/cookies. Captured hashes are exfiltrated to a Hashtopolis 0.7.2 server (observed on 85.11.187.8:8443) and cracked with Hashcat across a pool of ~10 RTX 4090 GPUs rented from Vast.ai, with a 4,525-line Telegram bot (bot.py / 'Telegram Hashcat Bot, NetNTLMv2 Cracker v10') providing live telemetry to a single hardcoded administrator.

For persistence the actor plants rogue administrator accounts on thousands of devices using names that masquerade as Fortinet services (forticloud-sync, forticloud-tech, support_fortinet, Technical_support, fortinetadmin, tech-fortinet, fgtsecure, fgtsec); the most frequent planted credential pairs include adminin:ITAdmin@888 (~3,947 devices), fortiAdmin:fortiAdmin1qaz2wsx (~1,282 devices) and fgtsecure:F0rt!n3tS3cur3! (~1,152 devices). Post-exploitation pivots through OpenFortiVPN client configs (vpn5.conf) and an Impacket-based toolkit (ad_full_audit.py, spray_da.py, spray_taroko.py, spider.py) to reach Active Directory, password-spray domain accounts, and recursively spider network shares; an autonomous AI pentest agent named CyberStrike automates parts of the chain. Anti-forensic options (delete_txt, delete_pcapng) remove capture artifacts. Reported scale spans 73,932+ firewall URLs across 194 countries, ~21,632 affected domains, 110M+ harvested credentials, ~21,976 devices with confirmed administrative access (the majority via SSH/22), 623 domains showing AD-compromise evidence, and a confirmed breach of a NATO-aligned defense contractor. No CVE is assigned; the campaign exploits exposed management surfaces, weak/reused credentials, and missing MFA rather than a single software flaw.

MITRE ATT&CK techniques used in TL-2026-0918

Discovery

T1018 Remote System Discovery; T1087 Account Discovery

Lateral Movement

T1021 Remote Services

Collection

T1039 Data from Network Shared Drive; T1557 Adversary-in-the-Middle

Credential Access

T1040 Network Sniffing; T1110 Brute Force; T1557 Adversary-in-the-Middle; T1558 Steal or Forge Kerberos Tickets

Exfiltration

T1041 Exfiltration Over C2 Channel

Defense Evasion

T1070 Indicator Removal

Command and Control

T1071 Application Layer Protocol; T1102 Web Service

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Persistence

T1098 Account Manipulation; T1136 Create Account

privilege-escalation

T1548 Abuse Elevation Control Mechanism

Resource Development

T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1588 Obtain Capabilities

Reconnaissance

T1595 Active Scanning

Affected products and versions in FortiBleed: Russian Initial-Access-Broker

  • Fortinet — FortiGate (FortiOS) firewall / SSL VPN gateway
    Vulnerable versions: Internet-exposed management interfaces / SSL VPN on FortiOS prior to current fixed release
    Fixed in: FortiOS 7.6.0+ (with management interface removed from public internet and MFA enforced)

Remediation for FortiBleed: Russian Initial-Access-Broker

Patches

  • Update FortiOS to the latest fixed release (7.6.0 or later as advised by Fortinet)

Immediate actions

  • Take FortiGate/SSL VPN management interfaces off the public internet; restrict to trusted management networks/VPN only
  • Audit all FortiGate administrator accounts and remove any not explicitly created by your team (especially forticloud-sync, forticloud-tech, support_fortinet, Technical_support, fortinetadmin, tech-fortinet, fgtsecure, fgtsec)
  • Rotate ALL FortiGate admin and local user credentials and force VPN re-authentication
  • Block outbound connections to 85.11.187.8 and hunt for prior contact

Workarounds

  • Where rebuild is required, disconnect affected devices from the internet and rebuild from scratch (factory reset + reconfigure)
  • Rotate IPsec site-to-site VPN tunnel keys/certificates at BOTH ends

Longer-term hardening

  • Enforce phishing-resistant MFA on all VPN and device-management logins
  • Deploy behavioral monitoring for FortiGate session-cookie reuse, single-IP admin logins, AS-REP/Kerberoast surges and C$ SMB scanning
  • Segment management plane from user/server VLANs and monitor AD for unauthorized accounts and privilege escalation

Weaknesses (CWE) in FortiBleed: Russian Initial-Access-Broker

CWE-1392, CWE-522, CWE-307, CWE-798, CWE-262

Timeline of FortiBleed: Russian Initial-Access-Broker

  • FortiBleed credential-harvesting activity assessed as active since at least February 2026, abusing exposed FortiGate management interfaces and reused/leaked credentials.
  • Heaviest observed operational window begins; intensive scanning, sniffing and hash-cracking concentrated between 19 May and 7 June 2026.
  • Snapshot of attacker staging server data; cumulative figures include ~73,932 firewall URLs across 194 countries and 110M+ harvested credentials.
  • FortiBleed campaign publicly disclosed; credential exposure across tens of thousands of FortiGate systems reported.
  • PwnDefend independently corroborates 85.11.187.8 as a source IP associated with FortiBleed credential-harvesting and cracking infrastructure.
  • Attacker staging/Hashtopolis server found exposed, revealing FortigateSniffer/harvest_orig binaries, bot.py Telegram cracker, Impacket scripts and planted-account data.
  • Detailed technical breakdowns published (Recorded Future/Insikt, SOCRadar STRU, ZenoX, BleepingComputer, SecurityWeek), attributing the operation to a Russian-origin initial access broker.
  • Help Net Security publishes investigation-and-remediation guidance; defenders urged to remove rogue admin accounts, rebuild compromised devices, enforce MFA and rotate IPsec keys.

Sources cited for FortiBleed: Russian Initial-Access-Broker

Threats related to FortiBleed: Russian Initial-Access-Broker

Detection coverage for TL-2026-0918

As of 2026-06-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0918 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-0918

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats