FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet' (FortigateSniffer) to Harvest 110M+ Credentials From ~430,000 FortiGate Firewalls — Threadlinqs Intelligence
As of 2026-06-24, FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet' (FortigateSniffer) to Harvest 110M+ Credentials From ~430,000 FortiGate Firewalls is a critical-severity threat intel threat attributed to Russian-speaking Initial Access Broker, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-0927 · Severity: CRITICAL · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Russian-speaking Initial Access Broker · FINANCIAL
FortiBleed is an active, financially motivated credential-harvesting operation in which a Russian-speaking initial access broker (handle 'SantaAd') turns compromised internet-facing Fortinet FortiGate
FortiBleed is a large-scale, ongoing initial-access-broker (IAB) operation documented by the SOCRadar Threat Research Unit (STRU) and corroborated by Dark Reading, BleepingComputer, The Hacker News, SecurityWeek, Security Affairs, GBHackers, and CyberSecurityNews. It has been active since at least February 2026, with multi-vendor internet-wide scanning observed from 28 February 2026.
The operation is built around FortigateSniffer (also referenced as fg_sniffer / SNIFTRAN engine), a Golang implant that abuses the legitimate FortiOS diagnostic command 'diagnose sniffer packet'. Rather than exploiting a software vulnerability, the actor gains administrative access to internet-facing FortiGate devices (typically via SSH brute force, dictionary attacks, and SSL-VPN credential stuffing using a custom 'forticheck' utility running up to 25,000 threads), then runs the firewall's own packet sniffer to passively capture cleartext credentials and authentication hashes traversing the device. The sniffer monitors 24 protocols — including TACACS+, Kerberos, RADIUS, NTLM, RPC, SMB, LDAP, SMTP, FTP, Telnet, RDP, WinRM, MS-SQL, MySQL, and PostgreSQL — and applies geofencing/IP-range filters. It runs in 300-minute (5-hour) capture cycles with minute-by-minute status reporting, operating roughly 07:00–18:00 Moscow Time, with an initial validation success rate near 90%.
The five-stage attack chain is: (1) Reconnaissance with Masscan and Shodan, device fingerprinting via FortiProbe-fast, and revenue/economic-value-based target prioritization; (2) Initial access via SSH brute force and SSL-VPN credential stuffing (forticheck); (3) Deployment of FortigateSniffer (observed on ~6,127 devices) to passively harvest credentials across 24 protocols; (4) Distributed GPU hash cracking via a Hashtopolis-managed Hashcat cluster augmented with dynamically rented vast.ai capacity (1–6 GPUs), orchestrated through a Telegram bot (HASHBOT) delivering live cracking telemetry to a single hardcoded administrator, followed by Active Directory enumeration; (5) Exfiltration of DFS/SMB network shares and persistence via stolen/replayed session cookies.
Reported harvest volumes include ~14.8M RADIUS credentials, ~924,000 NTLM hashes, ~130,000 Kerberos hashes, and ~89M MySQL authentication tokens, totaling 110M+ credentials. SecurityWeek/CISA confirm 86,644 working credentials across 194 countries (~50% of internet-facing Fortinet firewalls by Shodan polling), with India and the United States accounting for roughly a third of entries; telecom, government, banking, healthcare, and universities are among affected sectors, weighted toward SMBs (~66% under 200 employees). A NATO-aligned defense contractor breach with data exfiltration was confirmed on 15 June 2026. Attribution to a Russian-speaking IAB is assessed at MEDIUM confidence based on Cyrillic comments in the tooling, Moscow-time operating windows, Eastern European micro-hoster infrastructure (Russian and Ukrainian networks), and an underground actor 'SantaAd' advertising Fortinet device access at $30,000–$60,000. CISA issued an urgent advisory (18 June 2026) urging organizations to terminate sessions, reset credentials, move admin password storage to PBKDF2, enable phishing-resistant MFA, and restrict management access.
Weaknesses (CWE)
CWE-798, CWE-522, CWE-307, CWE-319, CWE-1392
Target sectors: telecommunications, government, banking, healthcare, education, defense, it-services, critical-infrastructure
Target regions: North America, South Asia, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
THREAT_INTEL, CRITICAL, threat intelligence, cybersecurity, T1595, T1595.001, T1596, T1592, T1583.004, T1588.002, T1587.001, T1078, T1133, T1110