FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operations
FortiBleed Credential-Harvesting Campaign Feeds INC Ransom (TL-2026-1056), also tracked as FortiBleed, is a critical-severity ransomware operation, first published 2026-07-02. It is attributed to FortiBleed IAB (Russia) with medium confidence, affects Fortinet FortiGate (FortiOS), maps to 30 MITRE ATT&CK techniques (T1016, T1018, T1021.001), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-1056
- Threat ID
- TL-2026-1056
- Also known as
- FortiBleed, FortiGate Sniffer Campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-07-02
- Last reviewed
- 2026-07-02
- Attribution
- FortiBleed IAB
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- health, education, government administration, defense, manufacturing, itservices, finance, smallandmediumbusiness
- Target regions
- North America, Europe, Asia-Pacific, Middle East, Latin America, india, taiwan, united states of america
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in FortiBleed Credential-Harvesting Campaign Feeds INC Ransom
Malware and tooling: FortigateSniffer, Lynx Ransomware, inc ransom, CyberStrike, FortiProbe-fast, Hashcat, Hashtopolis, MEGAsync, Masscan, Rclone - S1040, Shodan
A Russian-speaking Initial Access Broker's FortiBleed campaign has weaponized the legitimate FortiOS `diagnose sniffer packet` diagnostic command via a custom Golang tool, FortigateSniffer, to passively harvest 110M+ authentication credentials from 430,000+ internet-facing FortiGate firewalls across 150+ countries. SOCRadar's Threat Research Unit (STRU) obtained an operational-security lapse that exposed the actor's infrastructure, tooling, and internal logs, revealing that harvested access is fed directly into at least 12 confirmed ransomware deployments and that a single operator held live negotiation-panel sessions for both the INC Ransom and Lynx RaaS operations.
How FortiBleed Credential-Harvesting Campaign Feeds INC Ransom works
FortiBleed is not a discrete CVE-driven vulnerability but a technique-abuse campaign: attackers repurpose FortiOS's built-in `diagnose sniffer packet` administrative command — normally used by network engineers to troubleshoot connectivity — to passively capture authentication traffic in cleartext and hashed form across roughly two dozen protocols (NTLM, Kerberos, RADIUS, RDP, LDAP, MSSQL) traversing compromised FortiGate appliances. The campaign begins with mass reconnaissance using Masscan and Shodan (via a custom Shodan_Recon enrichment tool and a FortiProbe-fast binary filter) to identify internet-exposed FortiGate management interfaces and SSL-VPN portals, alongside adjacent scanning of Sophos SSL-VPN and RDWeb portals. Operators then conduct SSH brute-force (using 16 FortiGate-convention wordlists) and credential-stuffing attacks against administrative and SSL-VPN accounts to obtain initial admin-level access. Once inside, they deploy FortigateSniffer — a Golang binary built for both Linux and Windows targets — to run the sniffer continuously, timed to operate only 07:00-18:00 Moscow time to blend with legitimate diagnostic traffic and administrator working hours. Captured hashes are shipped to a distributed GPU cracking cluster (Hashtopolis orchestrating Hashcat, with compute rented from vast.ai) and, per some reporting, a purpose-built CyberStrike automation framework. Cracked and replayed credentials (including session-cookie replay) are used to pivot from firewall admin access into VPN, then Active Directory domain controllers, culminating in domain-admin compromise; operators reportedly also planted persistent backdoor accounts named "adminin" for durable access. Post-compromise, actors traverse Active Directory, stage data via DFS backup shares, and exfiltrate before selling or directly monetizing access. Confirmed admin-level access was achieved on 409 targets and full attack-chain (domain) compromise on 354 organizations, out of roughly 80,000 identified and ~11,000-19,000 actively sniffed devices at peak (scaled down after vendor/researcher notification). Infrastructure spans 200-500+ operational servers hosted on Eastern European micro-hosting providers, segmented into distinct subnet blocks for C2 aggregation, credential validation, sniffer deployment, and proxy rotation; Cyrillic-language code comments and Russian/Ukrainian-hosted infrastructure support a Russian-origin assessment. The actor also leveraged a previously undisclosed Nextcloud zero-day for post-compromise access expansion, reportedly under coordinated/responsible disclosure, and is under investigation for AI-assisted vulnerability research. Victimology skews toward small-to-medium organizations (66% under 200 employees, 90% under $100M revenue) and IT/MSP services firms, with confirmed breaches extending to a NATO-aligned defense contractor (Kerberos hash cracking and data exfiltration confirmed June 15, 2026) and organizations in healthcare, education, and government sectors. SOCRadar's decisive finding is operational overlap: a Windows server within FortiBleed's own infrastructure retained active browser sessions logged into the negotiation/chat panels of both the INC Ransom and Lynx ransomware-as-a-service platforms, directly tying mass credential harvesting to at least 12 confirmed ransomware deployments with hundreds of endpoints encrypted. INC Ransom has operated as a RaaS platform since mid-2023, targeting industrial, healthcare, and education sectors via spearphishing, exploitation of internet-facing applications, RDP lateral movement, and Rclone/Megasync-based exfiltration ahead of double-extortion encryption. Lynx, which emerged roughly a year after INC and is widely assessed by researchers (Palo Alto Unit 42, Group-IB) as a rebrand/evolution of the INC codebase, uses Curve25519-Donna plus AES-128-CTR encryption, appends the `.lynx` extension to encrypted files, drops `README.txt` ransom notes, changes desktop wallpaper to `background-image.jpg`, and terminates backup/database services (MSSQL, Exchange, Veeam) and deletes Volume Shadow Copies prior to encryption. SOCRadar has indicated a forthcoming second technical whitepaper with additional IOCs and attribution evidence.
MITRE ATT&CK techniques used in TL-2026-1056
Discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1087.002 Domain Account
Lateral Movement
T1021.001 Remote Desktop Protocol; T1550 Use Alternate Authentication Material
Defense Evasion
T1036 Masquerading; T1070 Indicator Removal
Credential Access
T1040 Network Sniffing; T1110.002 Password Cracking; T1110.004 Credential Stuffing; T1552 Unsecured Credentials
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Collection
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Persistence
T1078 Valid Accounts; T1136.001 Local Account
Command and Control
T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer
credential-access
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery
lateral-movement
Exfiltration
T1567.002 Exfiltration to Cloud Storage
Resource Development
T1583.004 Server; T1587.001 Malware; T1588.002 Tool
Reconnaissance
T1595.001 Scanning IP Blocks; T1596 Search Open Technical Databases
Affected products and versions in FortiBleed Credential-Harvesting Campaign Feeds INC Ransom
- Fortinet — FortiGate (FortiOS)
Vulnerable versions: internet-exposed FortiOS management/SSL-VPN interfaces, versions unspecified by source
Fixed in: not applicable - technique abuse of legitimate diagnostic command, not a patchable CVE - Sophos — Sophos SSL-VPN / RDWeb portals
Vulnerable versions: scanned as adjacent reconnaissance targets - Nextcloud — Nextcloud
Vulnerable versions: unspecified - undisclosed zero-day leveraged for post-compromise access expansion
Fixed in: pending coordinated disclosure
Remediation for FortiBleed Credential-Harvesting Campaign Feeds INC Ransom
Patches
- Apply latest FortiOS firmware updates and Fortinet PSIRT guidance for the affected device fleet
- Patch or restrict access to any exposed Nextcloud instances pending vendor disclosure of the FortiBleed-associated zero-day
Immediate actions
- Rotate all FortiGate administrative and SSL-VPN credentials immediately, assuming compromise for any internet-exposed device
- Remove FortiGate management interfaces (GUI/SSH/API) from direct internet exposure; restrict to management VLAN or VPN-only access
- Enforce MFA on all FortiGate administrative and SSL-VPN accounts
- Audit for unauthorized local accounts, especially variants of the backdoor username 'adminin'
- Review FortiOS diagnose/CLI command execution logs for unexpected or scheduled 'diagnose sniffer packet' invocations, particularly during 07:00-18:00 Moscow time (04:00-15:00 UTC)
- Invalidate and rotate active session cookies/tokens for VPN and web-facing admin portals to defeat session-cookie replay
- Hunt for outbound connections to identified FortiBleed infrastructure IPs and for Rclone/Megasync/Tor egress patterns associated with INC/Lynx
Workarounds
- Disable or tightly restrict CLI/API access to the 'diagnose sniffer packet' command for non-administrative roles
- Use SOCRadar's free exposure checker or equivalent to identify FortiGate assets present in FortiBleed harvesting telemetry
Longer-term hardening
- Deploy EDR/NDR with behavioral detection for RDP lateral movement, LSASS/credential dumping, and mass file encryption patterns
- Implement network segmentation between perimeter firewalls, VPN concentrators, and domain controllers
- Establish centralized, tamper-resistant logging for FortiOS diagnostic command usage and administrative sessions
- Adopt immutable, offline backups and routinely test restoration to counter VSS deletion and backup-service termination
- Run periodic external attack-surface scans (Shodan/Censys) to identify unintentionally exposed management interfaces
Weaknesses (CWE) in FortiBleed Credential-Harvesting Campaign Feeds INC Ransom
CWE-200, CWE-522, CWE-306, CWE-1188
Timeline of FortiBleed Credential-Harvesting Campaign Feeds INC Ransom
- Earliest FortiBleed campaign artifacts observed; actor begins scanning Sophos SSL-VPN and RDWeb portals alongside FortiGate reconnaissance
- Sniffer infrastructure deployed and actively capturing traffic on approximately 19,000 FortiGate devices at campaign peak
- Offline Kerberos hash cracking completed and data exfiltrated from a NATO-aligned defense contractor via FortiBleed-derived access
- Recorded Future publishes early FortiBleed exposure findings covering ~73,932 affected FortiGate systems
- SOCRadar publicly discloses the FortiBleed campaign, reporting 86,644 compromised Fortinet firewalls and detailing FortigateSniffer tooling
- SecurityWeek and Security Affairs publish independent technical breakdowns attributing FortiBleed to a Russian-speaking Initial Access Broker
- SOCRadar Threat Research Unit publishes evidence that a FortiBleed operator held active negotiation-panel sessions for both INC Ransom and Lynx RaaS platforms, and discloses full campaign scale of 430,000+ targeted firewalls and 110 million+ harvested credentials
- Cyber Security News republishes and summarizes the SOCRadar findings, confirming 12+ ransomware deployments and 354 organizations with full attack-chain compromise
- SOCRadar indicates a forthcoming second technical whitepaper with additional IOCs, attribution evidence, and Nextcloud zero-day details is planned
Sources cited for FortiBleed Credential-Harvesting Campaign Feeds INC Ransom
- FortiBleed Password Stealing Attack Linked to INC and Lynx Ransomware Operations
- SOCRadar Links FortiBleed Campaign to INC and Lynx Ransomware Operations
- FortiBleed credential-theft campaign linked to Lynx ransomware
- FortiBleed: 86,644 Fortinet Firewalls Compromised — SOCRadar Research
- What Is FortiBleed? Fortinet Credential Theft Campaign Explained
- Dismantling FortiBleed: Inside a Russian Fortinet Compromise Operation
- FortiBleed campaign used custom FortiGate sniffer to steal credentials
- Russian Initial Access Broker Behind FortiBleed Campaign
- FortiBleed Campaign Uses FortigateSniffer to Harvest 110 Million Credentials From Fortinet Firewalls
- FortiBleed: The Most Detailed Breakdown Yet of an Active Russian Credential-Harvesting Operation
- FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist
- FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
- INC Ransom, GOLD IONIC, Group G1032 | MITRE ATT&CK
- Lynx Ransomware: Exposing How INC Ransomware Rebrands Itself
- Lynx Ransomware: A Rebranding of INC Ransomware - Unit 42
Threats related to FortiBleed Credential-Harvesting Campaign Feeds INC Ransom
- FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx Ransomware Operations
- FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware Operations
- FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx Ransomware
- FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet' (FortigateSniffer) to Harvest 110M+ Credentials From ~430,000 FortiGate Firewalls
- FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware Operations
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries)
Detection coverage for TL-2026-1056
As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1056 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1056
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.