FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware Operations — Threadlinqs Intelligence
As of 2026-07-02, FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware Operations is a critical-severity ransomware threat attributed to FortiBleed Operator (INC (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1085 · Severity: CRITICAL · Status: ACTIVE · Category: RANSOMWARE
Attribution: FortiBleed Operator (INC · Russia · FINANCIAL
SOCRadar's Threat Research Unit (STRU) linked the FortiBleed mass credential-harvesting campaign — which used a custom Golang packet sniffer abusing the FortiOS `diagnose sniffer packet` command
FortiBleed is a large-scale, financially motivated credential-harvesting operation active since at least February 2026 that abuses a legitimate FortiOS diagnostic feature — the `diagnose sniffer packet` command — via a custom Golang tool dubbed FortigateSniffer (also referenced as FortiGate Sniffer) to passively capture authentication traffic traversing compromised FortiGate firewalls. No FortiOS vulnerability or zero-day is required for initial compromise: threat actors gain access to devices through mass scanning (Masscan, Shodan, and a custom FortiProbe-fast filtering binary), SSH brute-forcing with FortiGate-specific wordlists, and SSL-VPN credential stuffing/dictionary attacks via a tool referred to as "forticheck." Once administrative access is obtained, the operators deploy FortigateSniffer to passively intercept authentication material across roughly two dozen protocols (Kerberos, NTLM, RADIUS, RDP, LDAP, TACACS+, RPC, SMB, SMTP, FTP, Telnet, WinRM, MS-SQL, MySQL, PostgreSQL) without dropping traditional malware, evading many endpoint-based detections.
SOCRadar's STRU discovered a persistent backdoor account (username "adminin", credential pair adminin:ITAdmin@888) planted on thousands of compromised devices — found on 3,947 distinct devices in a validated-credentials cache, including 1,562 instances in a single EU-focused batch — indicating provisioned rather than organically reused accounts. Harvested credentials (110+ million records, including 14.8M RADIUS, 924K NTLM hashes, 130K Kerberos hashes, and 89M MySQL authentication tokens) are processed through a Go-based ELF credential-extraction tool called CyberStrike Harvester v1.5, and password hashes are cracked at scale using Hashcat orchestrated through Hashtopolis against rented vast.ai GPU capacity, coordinated by a Telegram bot named HASHBOT. Operational tradecraft indicates a disciplined, professionalized crew: activity is geofenced and restricted to 07:00-18:00 Moscow time to blend with legitimate business traffic, tooling contains Cyrillic-language code comments suggesting Russian-speaking operators, and infrastructure is segmented across four subnet blocks hosted on Eastern European micro-hosting providers dedicated respectively to C2 aggregation, credential validation, sniffer deployment, and proxy rotation. Investigators also found a pentest-lab-style back-end (seven Kali Linux VMs under QEMU/KVM, hardened iptables, shared tmux sessions for multi-operator access) supporting an estimated 20-person team with defined roles.
The campaign has targeted more than 430,000 FortiGate devices across 150+ countries, with roughly 11,250 FortiGate portals actively scanned, admin-level access confirmed on 409 targets, and full domain compromise achieved on 354 of those — with traffic sniffers actively running on approximately 19,000 devices at peak (reduced to roughly 11,000 following vendor/CERT notifications). Between May 19 and June 15, 2026, at least 659 distinct credential-harvesting pipelines were launched. Post-compromise, operators pivot from firewall/VPN credential theft to Active Directory lateral movement, Kerberos hash cracking, and DFS backup exfiltration; SOCRadar also assesses the group may have exploited a previously undisclosed Nextcloud zero-day to expand access after initial compromise, though full technical details of that vulnerability have not been publicly released. A confirmed victim includes a NATO-aligned defense contractor, where exfiltration of DFS backup data began within minutes of an offline Kerberos hash crack completing. Victimology skews toward SMBs (66% under 200 employees, 90% under $100M revenue) concentrated in India, the United States, and Taiwan (~33% combined), with IT/MSP services as a primary target sector — likely valued for downstream access to MSP customer networks — alongside healthcare, education, and government targets identified via ransomware-panel overlap.
The pivotal escalation documented in this research: SOCRadar
Weaknesses (CWE)
CWE-798, CWE-306, CWE-522, CWE-1188, CWE-287
Target sectors: itservicesmsp, health, education, government administration, defense, finance, smbenterprise
Target regions: india, united states of america, taiwan, Europe, North America, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, T1595, T1587, T1583, T1585, T1078, T1133, T1190, T1110, T1110, T1040