FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx Ransomware Operations — Threadlinqs Intelligence
As of 2026-07-02, FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx Ransomware Operations is a critical-severity ransomware threat attributed to FortiBleed IAB Crew (feeding INC Ransom, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1090 · Severity: CRITICAL · Status: ACTIVE · Category: RANSOMWARE
Attribution: FortiBleed IAB Crew (feeding INC Ransom · FINANCIAL
SOCRadar's FortiBleed investigation links a mass credential-harvesting campaign against 430,000+ FortiGate firewalls worldwide to active ransomware deployments, after an operator was found logged into
FortiBleed is a large-scale credential-harvesting operation, publicly documented by SOCRadar on 2026-07-01, that targeted more than 430,000 internet-facing FortiGate firewalls across 150+ countries. The operators scanned roughly 11,250-11,000 FortiGate management portals, attempted brute-force logins with known/leaked credential combinations, and — where initial access was gained — deployed a custom Golang packet-sniffing tool (publicly referred to as 'FortigateSniffer' / 'FortiGate Sniffer') that abuses FortiOS's native `diagnose sniffer packet` CLI command to passively intercept authentication traffic across roughly two dozen network protocols. The sniffer was installed on an estimated 12,000-19,000 devices, and more than 110 million credentials are reported to have been harvested in total. Investigators also recovered a persistent backdoor account with the username 'adminin' used to maintain access on compromised firewalls, and evidence that the operators possess an undisclosed zero-day vulnerability in Nextcloud that is under active exploitation-in-development. Of the compromised firewalls, 409 yielded confirmed admin-level access and 354 were pushed through a full attack chain: VPN compromise, pivot to the internal domain controller, and escalation to domain admin. During a takedown/investigation of one FortiBleed staging server, SOCRadar found that an operator with FortiBleed infrastructure access was logged into the ransomware negotiation panels of both INC Ransom and Lynx ransomware, directly engaging with active ransom negotiations. Cross-referencing showed overlap between organizations whose credentials were harvested by FortiBleed and organizations later listed on the INC Ransom leak site, and researchers estimate ransomware deployment can follow initial credential theft within 30-60 days. At least 12 confirmed ransomware deployments and hundreds of encrypted endpoints have been attributed to the campaign so far. Lynx is assessed by multiple vendors (Unit 42, Picus, SOCRadar) as an evolved rebrand of INC Ransom rather than a wholly separate group, sharing a large portion of its codebase, AES-128-CTR + Curve25519 encryption scheme, and RaaS affiliate structure; INC/Lynx have historically gained initial access via exploitation of public-facing applications (e.g., CVE-2023-3519 in Citrix NetScaler) and spear-phishing, then used RDP and lateral tool transfer for lateral movement, 7-Zip/WinRAR staging, and Mega/cloud exfiltration ahead of double-extortion encryption (.inc / .lynx extensions). The FortiBleed operation itself is assessed as a Russian-speaking initial-access-broker (IAB) crew of roughly 20 personnel with defined roles — a small core of senior operators handling high-impact intrusions supported by specialists and junior staff — that discovered and monetized access by selling or directly feeding it into ransomware affiliates. SOCRadar identified over 200 additional operational servers (500 total) tied to the infrastructure beyond the original campaign, plus secondary reconnaissance against roughly 29,000 IPs and 37 domains associated with Citrix environments, and separately observed exploitation of CVE-2026-35616 (Fortinet FortiClient EMS, CVSS 9.1) tied to EKZ Stealer deployment in the same threat landscape. Primary targeted sectors include manufacturing, technology, and logistics, with a geographic skew toward Latin America and Asia-Pacific alongside the broader 150+-country scanning footprint. SOCRadar states full IOC disclosure and additional technical detail will follow in a forthcoming whitepaper; no CVE has yet been assigned to the FortiOS `diagnose sniffer packet` abuse technique itself.
Weaknesses (CWE)
CWE-522, CWE-311, CWE-287
Target sectors: manufacturing, technology, logistics, industrial, health, education, government administration, critical infrastructure
Target regions: Latin America, Asia Pacific, North America, Europe, Global
Related threats
- FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operations
- FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx Ransomware
- FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware Operations
- FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware Operations
- INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory)
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, CVE-2026-35616, CVE-2023-3519, T1190, T1566, T1133, T1110, T1557, T1040, T1552, T1136.001, T1078, T1685