FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operations — Threadlinqs Intelligence
As of 2026-07-02, FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operations is a critical-severity ransomware threat attributed to FortiBleed IAB (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1056 · Severity: CRITICAL · Status: ACTIVE · Category: RANSOMWARE
Attribution: FortiBleed IAB · Russia · FINANCIAL
A Russian-speaking Initial Access Broker's FortiBleed campaign has weaponized the legitimate FortiOS `diagnose sniffer packet` diagnostic command via a custom Golang tool, FortigateSniffer, to
FortiBleed is not a discrete CVE-driven vulnerability but a technique-abuse campaign: attackers repurpose FortiOS's built-in `diagnose sniffer packet` administrative command — normally used by network engineers to troubleshoot connectivity — to passively capture authentication traffic in cleartext and hashed form across roughly two dozen protocols (NTLM, Kerberos, RADIUS, RDP, LDAP, MSSQL) traversing compromised FortiGate appliances. The campaign begins with mass reconnaissance using Masscan and Shodan (via a custom Shodan_Recon enrichment tool and a FortiProbe-fast binary filter) to identify internet-exposed FortiGate management interfaces and SSL-VPN portals, alongside adjacent scanning of Sophos SSL-VPN and RDWeb portals. Operators then conduct SSH brute-force (using 16 FortiGate-convention wordlists) and credential-stuffing attacks against administrative and SSL-VPN accounts to obtain initial admin-level access. Once inside, they deploy FortigateSniffer — a Golang binary built for both Linux and Windows targets — to run the sniffer continuously, timed to operate only 07:00-18:00 Moscow time to blend with legitimate diagnostic traffic and administrator working hours. Captured hashes are shipped to a distributed GPU cracking cluster (Hashtopolis orchestrating Hashcat, with compute rented from vast.ai) and, per some reporting, a purpose-built CyberStrike automation framework. Cracked and replayed credentials (including session-cookie replay) are used to pivot from firewall admin access into VPN, then Active Directory domain controllers, culminating in domain-admin compromise; operators reportedly also planted persistent backdoor accounts named "adminin" for durable access. Post-compromise, actors traverse Active Directory, stage data via DFS backup shares, and exfiltrate before selling or directly monetizing access. Confirmed admin-level access was achieved on 409 targets and full attack-chain (domain) compromise on 354 organizations, out of roughly 80,000 identified and ~11,000-19,000 actively sniffed devices at peak (scaled down after vendor/researcher notification). Infrastructure spans 200-500+ operational servers hosted on Eastern European micro-hosting providers, segmented into distinct subnet blocks for C2 aggregation, credential validation, sniffer deployment, and proxy rotation; Cyrillic-language code comments and Russian/Ukrainian-hosted infrastructure support a Russian-origin assessment. The actor also leveraged a previously undisclosed Nextcloud zero-day for post-compromise access expansion, reportedly under coordinated/responsible disclosure, and is under investigation for AI-assisted vulnerability research. Victimology skews toward small-to-medium organizations (66% under 200 employees, 90% under $100M revenue) and IT/MSP services firms, with confirmed breaches extending to a NATO-aligned defense contractor (Kerberos hash cracking and data exfiltration confirmed June 15, 2026) and organizations in healthcare, education, and government sectors. SOCRadar's decisive finding is operational overlap: a Windows server within FortiBleed's own infrastructure retained active browser sessions logged into the negotiation/chat panels of both the INC Ransom and Lynx ransomware-as-a-service platforms, directly tying mass credential harvesting to at least 12 confirmed ransomware deployments with hundreds of endpoints encrypted. INC Ransom has operated as a RaaS platform since mid-2023, targeting industrial, healthcare, and education sectors via spearphishing, exploitation of internet-facing applications, RDP lateral movement, and Rclone/Megasync-based exfiltration ahead of double-extortion encryption. Lynx, which emerged roughly a year after INC and is widely assessed by researchers (Palo Alto Unit 42, Group-IB) as a rebrand/evolution of the INC codebase, uses Curve25519-Donna plus AES-128-CTR encryption, appends the `.lynx` extension to encrypted files, drops `README.txt` ransom notes, changes desktop wallpaper to `background-
Weaknesses (CWE)
CWE-200, CWE-522, CWE-306, CWE-1188
Target sectors: health, education, government administration, defense, manufacturing, itservices, finance, smallandmediumbusiness
Target regions: North America, Europe, Asia-Pacific, Middle East, Latin America, india, taiwan, united states of america
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, T1595.001, T1596, T1587.001, T1588.002, T1583.004, T1110, T1078, T1190, T1059, T1136.001