FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet' (FortigateSniffer) to Harvest 110M+ Credentials From ~430,000 FortiGate Firewalls
FortiBleed: Russian-Speaking Initial Access Broker (TL-2026-0927), also tracked as FortiBleed, is a critical-severity tracked intrusion set, first published 2026-06-24. It has no confirmed attribution, affects Fortinet FortiGate / FortiOS (internet-facing firewalls with exposed, maps to 26 MITRE ATT&CK techniques (T1018, T1021.001, T1021.002), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-0927
- Threat ID
- TL-2026-0927
- Also known as
- FortiBleed, FortigateSniffer campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-06-24
- Last reviewed
- 2026-06-24
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- telecommunications, government, banking, healthcare, education, defense, it-services, critical-infrastructure
- Target regions
- North America, South Asia, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in FortiBleed: Russian-Speaking Initial Access Broker
Malware and tooling: FortiProbe-fast, FortigateSniffer, GeoSplit, HASHBOT (Telegram bot), Hashcat, Hashtopolis
FortiBleed is an active, financially motivated credential-harvesting operation in which a Russian-speaking initial access broker (handle 'SantaAd') turns compromised internet-facing Fortinet FortiGate firewalls into passive credential collectors. After brute-forcing SSH/SSL-VPN admin access, the actor deploys FortigateSniffer, a Golang tool that abuses the built-in FortiOS 'diagnose sniffer packet' diagnostic to intercept authentication traffic across 24 protocols. SOCRadar reports ~430,000 targeted firewalls, 110M+ surfaced credentials across 659+ pipelines, and 86,644 confirmed working credentials spanning 194 countries — including a NATO-aligned defense contractor. The campaign relies on weak/harvested credentials and abuse of a legitimate feature, not a CVE or zero-day.
How FortiBleed: Russian-Speaking Initial Access Broker works
FortiBleed is a large-scale, ongoing initial-access-broker (IAB) operation documented by the SOCRadar Threat Research Unit (STRU) and corroborated by Dark Reading, BleepingComputer, The Hacker News, SecurityWeek, Security Affairs, GBHackers, and CyberSecurityNews. It has been active since at least February 2026, with multi-vendor internet-wide scanning observed from 28 February 2026.
The operation is built around FortigateSniffer (also referenced as fg_sniffer / SNIFTRAN engine), a Golang implant that abuses the legitimate FortiOS diagnostic command 'diagnose sniffer packet'. Rather than exploiting a software vulnerability, the actor gains administrative access to internet-facing FortiGate devices (typically via SSH brute force, dictionary attacks, and SSL-VPN credential stuffing using a custom 'forticheck' utility running up to 25,000 threads), then runs the firewall's own packet sniffer to passively capture cleartext credentials and authentication hashes traversing the device. The sniffer monitors 24 protocols — including TACACS+, Kerberos, RADIUS, NTLM, RPC, SMB, LDAP, SMTP, FTP, Telnet, RDP, WinRM, MS-SQL, MySQL, and PostgreSQL — and applies geofencing/IP-range filters. It runs in 300-minute (5-hour) capture cycles with minute-by-minute status reporting, operating roughly 07:00–18:00 Moscow Time, with an initial validation success rate near 90%.
The five-stage attack chain is: (1) Reconnaissance with Masscan and Shodan, device fingerprinting via FortiProbe-fast, and revenue/economic-value-based target prioritization; (2) Initial access via SSH brute force and SSL-VPN credential stuffing (forticheck); (3) Deployment of FortigateSniffer (observed on ~6,127 devices) to passively harvest credentials across 24 protocols; (4) Distributed GPU hash cracking via a Hashtopolis-managed Hashcat cluster augmented with dynamically rented vast.ai capacity (1–6 GPUs), orchestrated through a Telegram bot (HASHBOT) delivering live cracking telemetry to a single hardcoded administrator, followed by Active Directory enumeration; (5) Exfiltration of DFS/SMB network shares and persistence via stolen/replayed session cookies.
Reported harvest volumes include ~14.8M RADIUS credentials, ~924,000 NTLM hashes, ~130,000 Kerberos hashes, and ~89M MySQL authentication tokens, totaling 110M+ credentials. SecurityWeek/CISA confirm 86,644 working credentials across 194 countries (~50% of internet-facing Fortinet firewalls by Shodan polling), with India and the United States accounting for roughly a third of entries; telecom, government, banking, healthcare, and universities are among affected sectors, weighted toward SMBs (~66% under 200 employees). A NATO-aligned defense contractor breach with data exfiltration was confirmed on 15 June 2026. Attribution to a Russian-speaking IAB is assessed at MEDIUM confidence based on Cyrillic comments in the tooling, Moscow-time operating windows, Eastern European micro-hoster infrastructure (Russian and Ukrainian networks), and an underground actor 'SantaAd' advertising Fortinet device access at $30,000–$60,000. CISA issued an urgent advisory (18 June 2026) urging organizations to terminate sessions, reset credentials, move admin password storage to PBKDF2, enable phishing-resistant MFA, and restrict management access.
MITRE ATT&CK techniques used in TL-2026-0927
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1087 Account Discovery
Lateral Movement
T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares; T1550.004 Web Session Cookie
Collection
T1039 Data from Network Shared Drive; T1056 Input Capture
Credential Access
T1040 Network Sniffing; T1110 Brute Force; T1110.001 Password Guessing; T1110.004 Credential Stuffing; T1557 Adversary-in-the-Middle
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
Initial Access
T1078 Valid Accounts; T1133 External Remote Services
Defense Evasion
Resource Development
T1583.004 Server; T1587.001 Malware; T1588.002 Tool
Reconnaissance
T1592 Gather Victim Host Information; T1595 Active Scanning; T1595.001 Scanning IP Blocks; T1596 Search Open Technical Databases
Affected products and versions in FortiBleed: Russian-Speaking Initial Access Broker
- Fortinet — FortiGate / FortiOS (internet-facing firewalls with exposed SSH or SSL-VPN management)
Vulnerable versions: Any FortiOS exposing SSH/SSL-VPN admin with weak or harvested credentials
Fixed in: N/A — no software fix; abuse of legitimate feature + weak credentials
Remediation for FortiBleed: Russian-Speaking Initial Access Broker
Patches
- No CVE/patch applies — this campaign abuses weak credentials and a legitimate built-in FortiOS feature, not a software vulnerability. Keep FortiOS current per Fortinet PSIRT regardless.
Immediate actions
- Terminate all active SSL-VPN and admin sessions on internet-facing FortiGate devices and force a full credential reset
- Treat all credentials that traversed a potentially compromised FortiGate as exposed; rotate them platform-wide (admin, RADIUS, LDAP, Kerberos/NTLM service accounts, MS-SQL/MySQL/PostgreSQL)
- Hunt for unauthorized 'diagnose sniffer packet' usage and unexpected SSH logins to FortiGate admin accounts
- Block the known FortiBleed IPs (85.11.187.8, 193.8.187.2, 193.8.187.42, 193.8.187.26, 194.113.39.71, 77.91.122.13) at the perimeter
- Invalidate and rotate session cookies to defeat session-replay persistence
Workarounds
- Restrict trusted-host/management access on FortiGate to known admin source IPs
- Disable or tightly audit access to diagnostic sniffer functionality for non-essential admin accounts
- Monitor for the operator's 07:00–18:00 Moscow Time activity windows and 5-hour capture cycles in firewall logs
Longer-term hardening
- Remove management/SSL-VPN interfaces from direct internet exposure; place behind VPN allow-lists or zero-trust access
- Enforce phishing-resistant MFA on all FortiGate administrative and SSL-VPN access
- Migrate admin password storage to PBKDF2 and enforce strong, unique credentials
- Deploy network and host telemetry to detect credential sniffing and AD enumeration; segment management networks
Weaknesses (CWE) in FortiBleed: Russian-Speaking Initial Access Broker
CWE-798, CWE-522, CWE-307, CWE-319, CWE-1392
Timeline of FortiBleed: Russian-Speaking Initial Access Broker
- FortiBleed operation assessed active since at least February 2026 (SOCRadar STRU).
- Multi-vendor internet-wide scanning and automated brute-forcing begins, targeting FortiGate, Sophos, Citrix SSL-VPN, RDWeb, Synology NAS, and MS-SQL.
- FortigateSniffer credential capture cycles begin on compromised FortiGate devices.
- Major harvesting operation; large batches of captured authentication traffic processed.
- Confirmed data exfiltration from a NATO-aligned defense contractor via DFS/SMB share extraction.
- SOCRadar publishes initial FortiBleed report citing 86,644 confirmed credentials across 194 countries.
- CISA issues urgent advisory urging session termination, credential reset, PBKDF2 admin hashing, MFA, and restricted management access.
- SecurityWeek reports 86,000+ Fortinet device credentials compromised; ~50% of internet-facing Fortinet firewalls.
- SOCRadar releases full whitepaper detailing the five-stage chain, FortigateSniffer internals, infrastructure, and IOCs (430,000 firewalls, 110M+ credentials).
- Dark Reading and other outlets report on FortiBleed turning firewalls into credential stealers.
Sources cited for FortiBleed: Russian-Speaking Initial Access Broker
- Dismantling FortiBleed: Inside a Russian Fortinet Compromise Operation (Whitepaper)
- FortiBleed 2026: The Compromise of 86,644 Fortinet FortiGate Firewalls and Credential Leak
- FortiBleed Attackers Turn Firewalls Into Credentials Stealers
- FortiBleed: 86,000 Fortinet Device Credentials Compromised
- FortiBleed campaign used custom FortiGate sniffer to steal credentials
- FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
- FortiBleed Campaign Uses FortigateSniffer to Harvest 110 Million Credentials From Fortinet Firewalls
- FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation
- Hackers Using FortigateSniffer Tool That Turns Compromised Firewalls Into Password Collectors
Threats related to FortiBleed: Russian-Speaking Initial Access Broker
- FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operations
- FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN Firewalls Across 194 Countries
- FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware Operations
- FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx Ransomware
- FortiBleed Campaign: Custom FortigateSniffer Abuses FortiOS 'diagnose sniffer packet' to Harvest Credentials Across 24 Protocols
- FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN Gateways
Detection coverage for TL-2026-0927
As of 2026-06-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0927 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0927
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.