A Russian initial access broker (IAB) has been identified as the driving force behind the FortiBleed credential-harvesting campaign, which targets over 430,000 FortiGate firewalls globally. According to a report from SOCRadar, the campaign has been active since at least February 2023 and represents a multi-vendor operation aimed at compromising exposed network edge devices to steal authentication data.
The threat actor, likely motivated by financial gain, exploits vulnerable FortiGate appliances by conducting SSH brute-force attacks. Once access is gained, they deploy custom sniffers to capture cleartext credentials and password hashes traversing the firewall. The harvested data is then cracked, validated, and sold to other malicious actors, including ransomware gangs and potentially state-sponsored groups.
Initial access brokers play a critical role in the cybercrime ecosystem, often serving as the first point of entry for larger attacks. By compromising perimeter devices like firewalls, they can bypass traditional defenses and gain a foothold inside corporate networks. The FortiBleed campaign highlights how such brokers evolve their techniques to maximize impact.
Scope and Tools of the Campaign
SOCRadar’s investigation revealed that the attackers have scanned over 430,000 FortiGate firewalls, with approximately 80,000 identified as potential targets. Of these, more than 19,000 remain actively monitored using a custom-built tool called FortigateSniffer. This Golang-based utility abuses a legitimate FortiOS diagnostic command to passively capture authentication traffic across 24 protocols, including SSH, RDP, MSSQL, and Kerberos.
The campaign extends beyond Fortinet devices. SOCRadar found that the attackers also target Sophos SSL-VPN portals, RDWeb interfaces, and other remote access solutions. This multi-vendor approach allows them to harvest credentials from a wide range of environments, increasing the value of the stolen data. The earliest evidence dates back to February, with scans of Sophos SSL-VPN and RDWeb portals.
The attackers maintain two primary credential sources: one combines data from previous breaches with purchased datasets, while the other includes 16 custom dictionaries tailored for FortiGate admin accounts. This dual strategy enhances their ability to crack passwords and gain access to sensitive systems.
Attack Chain and Impact
The attack chain begins with reconnaissance using tools like Masscan and Shodan to identify vulnerable FortiGate appliances. After compromising a device via SSH brute-force, the attackers deploy network sniffers to capture credentials. They then crack password hashes using offline methods, validate the credentials, and use them for lateral movement against Active Directory domains and other services.
Once inside, the attackers exfiltrate sensitive data from network shares and rely on stolen session cookies to maintain persistent access. SOCRadar estimates that over 110 million credentials have been compromised so far, a figure that underscores the scale of the operation. The campaign particularly impacts small and medium-sized businesses (SMBs) with fewer than 200 employees, as well as managed service providers (MSPs) and IT services firms that manage Fortinet devices for multiple clients.
On June 15, the attackers successfully cracked Kerberos hashes and exfiltrated DFS backup data from a NATO-aligned defense contractor. This incident suggests a potential link to Russian state-sponsored groups, though the primary motivation appears financial. The stolen access could also be sold to ransomware affiliates, amplifying the threat.
Geographic and Sector Focus
While the campaign targets organizations worldwide, SOCRadar noted a heavy focus on the United States and India. Sectors including healthcare, finance, manufacturing, and education are frequently affected. The attackers prioritize SMBs due to their often weaker security postures, but larger enterprises are not immune if they expose FortiGate appliances to the internet.
The use of legitimate diagnostic commands for sniffing makes detection challenging. FortiGate administrators may not notice unusual activity unless they monitor diagnostic command usage closely. SOCRadar recommends restricting SSH access to firewalls, implementing multi-factor authentication, and regularly auditing logs for suspicious behavior.
Broader Implications and Mitigation
The FortiBleed campaign serves as a stark reminder of the risks associated with exposed network edge devices. Firewalls, VPNs, and other perimeter appliances are prime targets for initial access brokers. Organizations must treat these devices as critical assets and apply security best practices, including timely patching, strong authentication, and network segmentation.
From a supply chain perspective, MSPs and IT service providers are particularly vulnerable, as a compromise at their level can cascade to multiple clients. The attackers’ ability to sniffer credentials across 24 protocols means that a single firewall breach can expose an entire identity infrastructure.
The role of artificial intelligence in the campaign is also notable. SOCRadar indicated that FortigateSniffer was likely developed with assistance from an AI-powered penetration testing agent called CyberStrike. This suggests that attackers are leveraging advanced tools to automate and enhance their capabilities.
As the cybersecurity community continues to track FortiBleed, organizations are urged to review their firewall configurations and consider shutting down unnecessary services. The campaign is ongoing, and the stolen credentials may be used in future attacks for months or years to come.
Source: SecurityWeek News