FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operations

FortiBleed Credential-Harvesting Campaign Feeds INC Ransom (TL-2026-1056), also tracked as FortiBleed, is a critical-severity ransomware operation, first published 2026-07-02. It is attributed to FortiBleed IAB (Russia) with medium confidence, affects Fortinet FortiGate (FortiOS), maps to 30 MITRE ATT&CK techniques (T1016, T1018, T1021.001), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-1056

Threat ID
TL-2026-1056
Also known as
FortiBleed, FortiGate Sniffer Campaign
Severity
CRITICAL
Status
ACTIVE
Category
RANSOMWARE
First published
2026-07-02
Last reviewed
2026-07-02
Attribution
FortiBleed IAB
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
health, education, government administration, defense, manufacturing, itservices, finance, smallandmediumbusiness
Target regions
North America, Europe, Asia-Pacific, Middle East, Latin America, india, taiwan, united states of america
Detection rules
9
Indicators of compromise
27

Malware and tooling in FortiBleed Credential-Harvesting Campaign Feeds INC Ransom

Malware and tooling: FortigateSniffer, Lynx Ransomware, inc ransom, CyberStrike, FortiProbe-fast, Hashcat, Hashtopolis, MEGAsync, Masscan, Rclone - S1040, Shodan

A Russian-speaking Initial Access Broker's FortiBleed campaign has weaponized the legitimate FortiOS `diagnose sniffer packet` diagnostic command via a custom Golang tool, FortigateSniffer, to passively harvest 110M+ authentication credentials from 430,000+ internet-facing FortiGate firewalls across 150+ countries. SOCRadar's Threat Research Unit (STRU) obtained an operational-security lapse that exposed the actor's infrastructure, tooling, and internal logs, revealing that harvested access is fed directly into at least 12 confirmed ransomware deployments and that a single operator held live negotiation-panel sessions for both the INC Ransom and Lynx RaaS operations.

How FortiBleed Credential-Harvesting Campaign Feeds INC Ransom works

FortiBleed is not a discrete CVE-driven vulnerability but a technique-abuse campaign: attackers repurpose FortiOS's built-in `diagnose sniffer packet` administrative command — normally used by network engineers to troubleshoot connectivity — to passively capture authentication traffic in cleartext and hashed form across roughly two dozen protocols (NTLM, Kerberos, RADIUS, RDP, LDAP, MSSQL) traversing compromised FortiGate appliances. The campaign begins with mass reconnaissance using Masscan and Shodan (via a custom Shodan_Recon enrichment tool and a FortiProbe-fast binary filter) to identify internet-exposed FortiGate management interfaces and SSL-VPN portals, alongside adjacent scanning of Sophos SSL-VPN and RDWeb portals. Operators then conduct SSH brute-force (using 16 FortiGate-convention wordlists) and credential-stuffing attacks against administrative and SSL-VPN accounts to obtain initial admin-level access. Once inside, they deploy FortigateSniffer — a Golang binary built for both Linux and Windows targets — to run the sniffer continuously, timed to operate only 07:00-18:00 Moscow time to blend with legitimate diagnostic traffic and administrator working hours. Captured hashes are shipped to a distributed GPU cracking cluster (Hashtopolis orchestrating Hashcat, with compute rented from vast.ai) and, per some reporting, a purpose-built CyberStrike automation framework. Cracked and replayed credentials (including session-cookie replay) are used to pivot from firewall admin access into VPN, then Active Directory domain controllers, culminating in domain-admin compromise; operators reportedly also planted persistent backdoor accounts named "adminin" for durable access. Post-compromise, actors traverse Active Directory, stage data via DFS backup shares, and exfiltrate before selling or directly monetizing access. Confirmed admin-level access was achieved on 409 targets and full attack-chain (domain) compromise on 354 organizations, out of roughly 80,000 identified and ~11,000-19,000 actively sniffed devices at peak (scaled down after vendor/researcher notification). Infrastructure spans 200-500+ operational servers hosted on Eastern European micro-hosting providers, segmented into distinct subnet blocks for C2 aggregation, credential validation, sniffer deployment, and proxy rotation; Cyrillic-language code comments and Russian/Ukrainian-hosted infrastructure support a Russian-origin assessment. The actor also leveraged a previously undisclosed Nextcloud zero-day for post-compromise access expansion, reportedly under coordinated/responsible disclosure, and is under investigation for AI-assisted vulnerability research. Victimology skews toward small-to-medium organizations (66% under 200 employees, 90% under $100M revenue) and IT/MSP services firms, with confirmed breaches extending to a NATO-aligned defense contractor (Kerberos hash cracking and data exfiltration confirmed June 15, 2026) and organizations in healthcare, education, and government sectors. SOCRadar's decisive finding is operational overlap: a Windows server within FortiBleed's own infrastructure retained active browser sessions logged into the negotiation/chat panels of both the INC Ransom and Lynx ransomware-as-a-service platforms, directly tying mass credential harvesting to at least 12 confirmed ransomware deployments with hundreds of endpoints encrypted. INC Ransom has operated as a RaaS platform since mid-2023, targeting industrial, healthcare, and education sectors via spearphishing, exploitation of internet-facing applications, RDP lateral movement, and Rclone/Megasync-based exfiltration ahead of double-extortion encryption. Lynx, which emerged roughly a year after INC and is widely assessed by researchers (Palo Alto Unit 42, Group-IB) as a rebrand/evolution of the INC codebase, uses Curve25519-Donna plus AES-128-CTR encryption, appends the `.lynx` extension to encrypted files, drops `README.txt` ransom notes, changes desktop wallpaper to `background-image.jpg`, and terminates backup/database services (MSSQL, Exchange, Veeam) and deletes Volume Shadow Copies prior to encryption. SOCRadar has indicated a forthcoming second technical whitepaper with additional IOCs and attribution evidence.

MITRE ATT&CK techniques used in TL-2026-1056

Discovery

T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1087.002 Domain Account

Lateral Movement

T1021.001 Remote Desktop Protocol; T1550 Use Alternate Authentication Material

Defense Evasion

T1036 Masquerading; T1070 Indicator Removal

Credential Access

T1040 Network Sniffing; T1110.002 Password Cracking; T1110.004 Credential Stuffing; T1552 Unsecured Credentials

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Collection

T1074.002 Remote Data Staging

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Persistence

T1078 Valid Accounts; T1136.001 Local Account

Command and Control

T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer

credential-access

T1110 Brute Force

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery

lateral-movement

T1550.004 Web Session Cookie

Exfiltration

T1567.002 Exfiltration to Cloud Storage

Resource Development

T1583.004 Server; T1587.001 Malware; T1588.002 Tool

Reconnaissance

T1595.001 Scanning IP Blocks; T1596 Search Open Technical Databases

Affected products and versions in FortiBleed Credential-Harvesting Campaign Feeds INC Ransom

  • Fortinet — FortiGate (FortiOS)
    Vulnerable versions: internet-exposed FortiOS management/SSL-VPN interfaces, versions unspecified by source
    Fixed in: not applicable - technique abuse of legitimate diagnostic command, not a patchable CVE
  • Sophos — Sophos SSL-VPN / RDWeb portals
    Vulnerable versions: scanned as adjacent reconnaissance targets
  • Nextcloud — Nextcloud
    Vulnerable versions: unspecified - undisclosed zero-day leveraged for post-compromise access expansion
    Fixed in: pending coordinated disclosure

Remediation for FortiBleed Credential-Harvesting Campaign Feeds INC Ransom

Patches

  • Apply latest FortiOS firmware updates and Fortinet PSIRT guidance for the affected device fleet
  • Patch or restrict access to any exposed Nextcloud instances pending vendor disclosure of the FortiBleed-associated zero-day

Immediate actions

  • Rotate all FortiGate administrative and SSL-VPN credentials immediately, assuming compromise for any internet-exposed device
  • Remove FortiGate management interfaces (GUI/SSH/API) from direct internet exposure; restrict to management VLAN or VPN-only access
  • Enforce MFA on all FortiGate administrative and SSL-VPN accounts
  • Audit for unauthorized local accounts, especially variants of the backdoor username 'adminin'
  • Review FortiOS diagnose/CLI command execution logs for unexpected or scheduled 'diagnose sniffer packet' invocations, particularly during 07:00-18:00 Moscow time (04:00-15:00 UTC)
  • Invalidate and rotate active session cookies/tokens for VPN and web-facing admin portals to defeat session-cookie replay
  • Hunt for outbound connections to identified FortiBleed infrastructure IPs and for Rclone/Megasync/Tor egress patterns associated with INC/Lynx

Workarounds

  • Disable or tightly restrict CLI/API access to the 'diagnose sniffer packet' command for non-administrative roles
  • Use SOCRadar's free exposure checker or equivalent to identify FortiGate assets present in FortiBleed harvesting telemetry

Longer-term hardening

  • Deploy EDR/NDR with behavioral detection for RDP lateral movement, LSASS/credential dumping, and mass file encryption patterns
  • Implement network segmentation between perimeter firewalls, VPN concentrators, and domain controllers
  • Establish centralized, tamper-resistant logging for FortiOS diagnostic command usage and administrative sessions
  • Adopt immutable, offline backups and routinely test restoration to counter VSS deletion and backup-service termination
  • Run periodic external attack-surface scans (Shodan/Censys) to identify unintentionally exposed management interfaces

Weaknesses (CWE) in FortiBleed Credential-Harvesting Campaign Feeds INC Ransom

CWE-200, CWE-522, CWE-306, CWE-1188

Timeline of FortiBleed Credential-Harvesting Campaign Feeds INC Ransom

  • Earliest FortiBleed campaign artifacts observed; actor begins scanning Sophos SSL-VPN and RDWeb portals alongside FortiGate reconnaissance
  • Sniffer infrastructure deployed and actively capturing traffic on approximately 19,000 FortiGate devices at campaign peak
  • Offline Kerberos hash cracking completed and data exfiltrated from a NATO-aligned defense contractor via FortiBleed-derived access
  • Recorded Future publishes early FortiBleed exposure findings covering ~73,932 affected FortiGate systems
  • SOCRadar publicly discloses the FortiBleed campaign, reporting 86,644 compromised Fortinet firewalls and detailing FortigateSniffer tooling
  • SecurityWeek and Security Affairs publish independent technical breakdowns attributing FortiBleed to a Russian-speaking Initial Access Broker
  • SOCRadar Threat Research Unit publishes evidence that a FortiBleed operator held active negotiation-panel sessions for both INC Ransom and Lynx RaaS platforms, and discloses full campaign scale of 430,000+ targeted firewalls and 110 million+ harvested credentials
  • Cyber Security News republishes and summarizes the SOCRadar findings, confirming 12+ ransomware deployments and 354 organizations with full attack-chain compromise
  • SOCRadar indicates a forthcoming second technical whitepaper with additional IOCs, attribution evidence, and Nextcloud zero-day details is planned

Sources cited for FortiBleed Credential-Harvesting Campaign Feeds INC Ransom

Threats related to FortiBleed Credential-Harvesting Campaign Feeds INC Ransom

Detection coverage for TL-2026-1056

As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1056 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1056

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats