FortiBleed: Russian Initial-Access-Broker Credential-Harvesting Campaign Weaponizing FortiGate Firewalls with the FortigateSniffer Tool
FortiBleed: Russian Initial-Access-Broker (TL-2026-0918), also tracked as FortiBleed, is a high-severity tracked intrusion set, first published 2026-06-23. It is attributed to FortiBleed operator (Russia) with medium confidence, affects Fortinet FortiGate (FortiOS) firewall / SSL VPN gateway, maps to 22 MITRE ATT&CK techniques (T1018, T1021, T1039), and is covered by 9 detection rules and 28 indicators of compromise.
Key facts for TL-2026-0918
- Threat ID
- TL-2026-0918
- Also known as
- FortiBleed, FortigateSniffer campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-06-23
- Last reviewed
- 2026-06-23
- Attribution
- FortiBleed operator
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- government, defense, financial, healthcare, technology, telecommunications, managed-service-providers
- Target regions
- Global, North America, Europe, Asia, Middle East
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in FortiBleed: Russian Initial-Access-Broker
Malware and tooling: CyberStrike, FortigateSniffer, Hashcat, Hashtopolis, Impacket - S0357, Telegram Hashcat Bot (NetNTLMv2 Cracker v10)
FortiBleed is an active, financially motivated credential-harvesting operation in which a Russian-aligned initial access broker turned internet-exposed FortiGate firewalls and SSL VPN gateways into passive surveillance points. A custom Go tool (FortigateSniffer / harvest_orig) abuses the FortiOS 'diagnose sniffer packet' command to capture authentication traffic across 24 protocols; captured hashes are cracked on a Vast.ai-rented GPU cluster managed via Hashtopolis/Hashcat and orchestrated through a Telegram bot.
How FortiBleed: Russian Initial-Access-Broker works
FortiBleed is a large-scale, ongoing credential-compromise campaign against Fortinet FortiGate firewalls and SSL VPN gateways, first named publicly in mid-June 2026 after an attacker staging server was found exposed. The operator profile is consistent with a Russian-origin initial access broker (IAB) selling access to ransomware affiliates: tooling carries Cyrillic-language comments and the harvesting component only runs between 07:00 and 18:00 Moscow Time to blend with business-hours traffic.
Initial access is achieved by mass-scanning the internet (Masscan / custom Shodan_Recon / FortiProbe-fast) for FortiGate devices with exposed management interfaces, then authenticating with credentials sourced from prior Fortinet leaks and infostealer logs, or recovered by brute-force and GPU hash-cracking. Wordlists are curated for FortiGate admin naming conventions. Once a device is reached, the actor abuses the legitimate FortiOS diagnostic capability 'diagnose sniffer packet' via a Golang harvester (filename harvest_orig, a ~4.3 MB static ELF; a Windows/amd64 scanner variant also exists) to passively intercept authentication material for 24 protocols including NTLMv1/NTLMv2, Kerberos RC4/AES pre-auth, AS-REP, Kerberoast, HTTP Basic/Form/JSON, LDAP, MSSQL, MySQL, PostgreSQL, RADIUS, SNMP, RDP, WinRM, SSH, FTP, Telnet, SMTP, IMAP, POP3, and cleartext tokens/cookies. Captured hashes are exfiltrated to a Hashtopolis 0.7.2 server (observed on 85.11.187.8:8443) and cracked with Hashcat across a pool of ~10 RTX 4090 GPUs rented from Vast.ai, with a 4,525-line Telegram bot (bot.py / 'Telegram Hashcat Bot, NetNTLMv2 Cracker v10') providing live telemetry to a single hardcoded administrator.
For persistence the actor plants rogue administrator accounts on thousands of devices using names that masquerade as Fortinet services (forticloud-sync, forticloud-tech, support_fortinet, Technical_support, fortinetadmin, tech-fortinet, fgtsecure, fgtsec); the most frequent planted credential pairs include adminin:ITAdmin@888 (~3,947 devices), fortiAdmin:fortiAdmin1qaz2wsx (~1,282 devices) and fgtsecure:F0rt!n3tS3cur3! (~1,152 devices). Post-exploitation pivots through OpenFortiVPN client configs (vpn5.conf) and an Impacket-based toolkit (ad_full_audit.py, spray_da.py, spray_taroko.py, spider.py) to reach Active Directory, password-spray domain accounts, and recursively spider network shares; an autonomous AI pentest agent named CyberStrike automates parts of the chain. Anti-forensic options (delete_txt, delete_pcapng) remove capture artifacts. Reported scale spans 73,932+ firewall URLs across 194 countries, ~21,632 affected domains, 110M+ harvested credentials, ~21,976 devices with confirmed administrative access (the majority via SSH/22), 623 domains showing AD-compromise evidence, and a confirmed breach of a NATO-aligned defense contractor. No CVE is assigned; the campaign exploits exposed management surfaces, weak/reused credentials, and missing MFA rather than a single software flaw.
MITRE ATT&CK techniques used in TL-2026-0918
Discovery
T1018 Remote System Discovery; T1087 Account Discovery
Lateral Movement
Collection
T1039 Data from Network Shared Drive; T1557 Adversary-in-the-Middle
Credential Access
T1040 Network Sniffing; T1110 Brute Force; T1557 Adversary-in-the-Middle; T1558 Steal or Forge Kerberos Tickets
Exfiltration
T1041 Exfiltration Over C2 Channel
Defense Evasion
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Persistence
T1098 Account Manipulation; T1136 Create Account
privilege-escalation
T1548 Abuse Elevation Control Mechanism
Resource Development
T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1588 Obtain Capabilities
Reconnaissance
Affected products and versions in FortiBleed: Russian Initial-Access-Broker
- Fortinet — FortiGate (FortiOS) firewall / SSL VPN gateway
Vulnerable versions: Internet-exposed management interfaces / SSL VPN on FortiOS prior to current fixed release
Fixed in: FortiOS 7.6.0+ (with management interface removed from public internet and MFA enforced)
Remediation for FortiBleed: Russian Initial-Access-Broker
Patches
- Update FortiOS to the latest fixed release (7.6.0 or later as advised by Fortinet)
Immediate actions
- Take FortiGate/SSL VPN management interfaces off the public internet; restrict to trusted management networks/VPN only
- Audit all FortiGate administrator accounts and remove any not explicitly created by your team (especially forticloud-sync, forticloud-tech, support_fortinet, Technical_support, fortinetadmin, tech-fortinet, fgtsecure, fgtsec)
- Rotate ALL FortiGate admin and local user credentials and force VPN re-authentication
- Block outbound connections to 85.11.187.8 and hunt for prior contact
Workarounds
- Where rebuild is required, disconnect affected devices from the internet and rebuild from scratch (factory reset + reconfigure)
- Rotate IPsec site-to-site VPN tunnel keys/certificates at BOTH ends
Longer-term hardening
- Enforce phishing-resistant MFA on all VPN and device-management logins
- Deploy behavioral monitoring for FortiGate session-cookie reuse, single-IP admin logins, AS-REP/Kerberoast surges and C$ SMB scanning
- Segment management plane from user/server VLANs and monitor AD for unauthorized accounts and privilege escalation
Weaknesses (CWE) in FortiBleed: Russian Initial-Access-Broker
CWE-1392, CWE-522, CWE-307, CWE-798, CWE-262
Timeline of FortiBleed: Russian Initial-Access-Broker
- FortiBleed credential-harvesting activity assessed as active since at least February 2026, abusing exposed FortiGate management interfaces and reused/leaked credentials.
- Heaviest observed operational window begins; intensive scanning, sniffing and hash-cracking concentrated between 19 May and 7 June 2026.
- Snapshot of attacker staging server data; cumulative figures include ~73,932 firewall URLs across 194 countries and 110M+ harvested credentials.
- FortiBleed campaign publicly disclosed; credential exposure across tens of thousands of FortiGate systems reported.
- PwnDefend independently corroborates 85.11.187.8 as a source IP associated with FortiBleed credential-harvesting and cracking infrastructure.
- Attacker staging/Hashtopolis server found exposed, revealing FortigateSniffer/harvest_orig binaries, bot.py Telegram cracker, Impacket scripts and planted-account data.
- Detailed technical breakdowns published (Recorded Future/Insikt, SOCRadar STRU, ZenoX, BleepingComputer, SecurityWeek), attributing the operation to a Russian-origin initial access broker.
- Help Net Security publishes investigation-and-remediation guidance; defenders urged to remove rogue admin accounts, rebuild compromised devices, enforce MFA and rotate IPsec keys.
Sources cited for FortiBleed: Russian Initial-Access-Broker
- FortiBleed: investigation and remediation
- FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation
- Critical FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems (Insikt Group)
- Fortibleed: Anatomy of the FortiBleed campaign based on the server the attackers left exposed
- FortiBleed 2026: The Compromise of 86,644 Fortinet FortiGate Firewalls and Credential Leak (SOCRadar)
- Dismantling FortiBleed: Inside a Russian Fortinet Compromise Operation (SOCRadar STRU whitepaper)
- FortiBleed campaign used custom FortiGate sniffer to steal credentials
- FortiBleed Attackers Turn Firewalls Into Credential Stealers
- Russian Initial Access Broker Behind FortiBleed Campaign
- Technical Advisory: FortiBleed Credential Exposure Campaign Targeting Internet-Facing Fortinet Devices (Bitdefender)
- FortiBleed: Analysis of a Global Access Broker Campaign (SpyCloud)
- FortiBleed Campaign Uses FortigateSniffer to Harvest 110 Million Credentials From Fortinet Firewalls
Threats related to FortiBleed: Russian Initial-Access-Broker
- FortiBleed Campaign: Custom FortigateSniffer Abuses FortiOS 'diagnose sniffer packet' to Harvest Credentials Across 24 Protocols
- FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN Gateways
- FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware Operations
- FortiBleed — Credential Exposure Campaign Targeting Fortinet FortiGate Firewalls and SSL-VPN Gateways
- FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN Firewalls Across 194 Countries
- FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware Operations
Detection coverage for TL-2026-0918
As of 2026-06-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0918 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0918
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.