FortiBleed: Russian Initial-Access-Broker Credential-Harvesting Campaign Weaponizing FortiGate Firewalls with the FortigateSniffer Tool — Threadlinqs Intelligence
As of 2026-06-23, FortiBleed: Russian Initial-Access-Broker Credential-Harvesting Campaign Weaponizing FortiGate Firewalls with the FortigateSniffer Tool is a high-severity threat intel threat attributed to FortiBleed operator (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-0918 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: FortiBleed operator · Russia · FINANCIAL
FortiBleed is an active, financially motivated credential-harvesting operation in which a Russian-aligned initial access broker turned internet-exposed FortiGate firewalls and SSL VPN gateways into
FortiBleed is a large-scale, ongoing credential-compromise campaign against Fortinet FortiGate firewalls and SSL VPN gateways, first named publicly in mid-June 2026 after an attacker staging server was found exposed. The operator profile is consistent with a Russian-origin initial access broker (IAB) selling access to ransomware affiliates: tooling carries Cyrillic-language comments and the harvesting component only runs between 07:00 and 18:00 Moscow Time to blend with business-hours traffic.
Initial access is achieved by mass-scanning the internet (Masscan / custom Shodan_Recon / FortiProbe-fast) for FortiGate devices with exposed management interfaces, then authenticating with credentials sourced from prior Fortinet leaks and infostealer logs, or recovered by brute-force and GPU hash-cracking. Wordlists are curated for FortiGate admin naming conventions. Once a device is reached, the actor abuses the legitimate FortiOS diagnostic capability 'diagnose sniffer packet' via a Golang harvester (filename harvest_orig, a ~4.3 MB static ELF; a Windows/amd64 scanner variant also exists) to passively intercept authentication material for 24 protocols including NTLMv1/NTLMv2, Kerberos RC4/AES pre-auth, AS-REP, Kerberoast, HTTP Basic/Form/JSON, LDAP, MSSQL, MySQL, PostgreSQL, RADIUS, SNMP, RDP, WinRM, SSH, FTP, Telnet, SMTP, IMAP, POP3, and cleartext tokens/cookies. Captured hashes are exfiltrated to a Hashtopolis 0.7.2 server (observed on 85.11.187.8:8443) and cracked with Hashcat across a pool of ~10 RTX 4090 GPUs rented from Vast.ai, with a 4,525-line Telegram bot (bot.py / 'Telegram Hashcat Bot, NetNTLMv2 Cracker v10') providing live telemetry to a single hardcoded administrator.
For persistence the actor plants rogue administrator accounts on thousands of devices using names that masquerade as Fortinet services (forticloud-sync, forticloud-tech, support_fortinet, Technical_support, fortinetadmin, tech-fortinet, fgtsecure, fgtsec); the most frequent planted credential pairs include adminin:ITAdmin@888 (~3,947 devices), fortiAdmin:fortiAdmin1qaz2wsx (~1,282 devices) and fgtsecure:F0rt!n3tS3cur3! (~1,152 devices). Post-exploitation pivots through OpenFortiVPN client configs (vpn5.conf) and an Impacket-based toolkit (ad_full_audit.py, spray_da.py, spray_taroko.py, spider.py) to reach Active Directory, password-spray domain accounts, and recursively spider network shares; an autonomous AI pentest agent named CyberStrike automates parts of the chain. Anti-forensic options (delete_txt, delete_pcapng) remove capture artifacts. Reported scale spans 73,932+ firewall URLs across 194 countries, ~21,632 affected domains, 110M+ harvested credentials, ~21,976 devices with confirmed administrative access (the majority via SSH/22), 623 domains showing AD-compromise evidence, and a confirmed breach of a NATO-aligned defense contractor. No CVE is assigned; the campaign exploits exposed management surfaces, weak/reused credentials, and missing MFA rather than a single software flaw.
Weaknesses (CWE)
CWE-1392, CWE-522, CWE-307, CWE-798, CWE-262
Target sectors: government, defense, financial, healthcare, technology, telecommunications, managed-service-providers
Target regions: Global, North America, Europe, Asia, Middle East
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1595, T1595, T1583, T1588, T1586, T1190, T1133, T1078, T1110, T1110