News Daily Nation Digital News & Media Platform

collapse
Home / Daily News Analysis / Russian Initial Access Broker Behind FortiBleed Campaign

Russian Initial Access Broker Behind FortiBleed Campaign

Jul 22, 2026  Twila Rosenbaum  48 views
Russian Initial Access Broker Behind FortiBleed Campaign

A Russian initial access broker (IAB) has been identified as the primary actor behind the FortiBleed credential-harvesting campaign, which targets over 430,000 FortiGate firewalls worldwide. The campaign, discovered last week and ongoing since at least February 2024, was initially believed to be exclusive to Fortinet devices, but recent analysis reveals it is a multi-vendor operation focused on harvesting credentials and selling access to compromised networks.

According to a detailed report from SOCRadar, the threat actor uses a combination of tools and techniques to compromise FortiGate appliances. The attacker first scans the internet using Masscan and Shodan to identify vulnerable firewalls, then performs SSH brute-force attacks to gain initial access. Once inside, they deploy network sniffers to capture cleartext credentials and password hashes. The most critical tool in this operation is a custom Golang-based sniffer called FortigateSniffer, which abuses the legitimate FortiOS diagnostic command to passively capture authentication traffic across 24 different protocols, including SSH, HTTP, HTTPS, and telnet.

The campaign has already compromised over 19,000 of the 80,000 identified targets, and SOCRadar estimates that more than 110 million credentials have been stolen. The stolen credentials are then cracked, validated, and used for lateral movement within affected networks. The attackers also exfiltrate sensitive data from network shares and use stolen session cookies to maintain persistent access. The operation is financially motivated, with the IAB likely selling the stolen credentials and access to ransomware groups or other cybercriminals.

Initial Access Brokers and the Cybercrime Economy

Initial access brokers (IABs) play a crucial role in the cybercrime ecosystem. These actors specialize in gaining unauthorized access to corporate networks, often through techniques like credential theft, vulnerability exploitation, or brute-force attacks. They then sell that access to other criminals, such as ransomware gangs, who use it to deploy malware, exfiltrate data, and demand ransom. The FortiBleed campaign illustrates the sophistication of modern IAB operations, which now leverage custom tools and extensive infrastructure to scale their efforts.

IABs typically focus on perimeter devices like firewalls, VPNs, and remote access servers because these systems sit at the edge of corporate networks and often have direct access to critical internal resources. By compromising a firewall, an attacker can potentially monitor all traffic passing through it, including authentication data, and pivot to other systems. In the case of FortiBleed, the attacker targets not only FortiGate firewalls but also other vendors' SSL-VPNs, RDP portals, and services like MSSQL and Citrix. This multi-vendor approach increases the reach of the campaign and makes it harder for defenders to block.

Technical Details of the Attack

The FortiBleed campaign relies on several key components. First, the attacker uses Masscan and Shodan to identify FortiGate appliances with exposed management interfaces or known vulnerabilities. After gaining initial access via SSH brute-force attacks, they deploy the FortigateSniffer tool, which uses the FortiOS diagnostic command to capture packets on the firewall. The sniffer is reportedly built with assistance from an AI-powered autonomous penetration testing agent called CyberStrike, which helps optimize the tool for high-volume traffic capture.

Once credentials are captured, they are validated against Active Directory domains and other services. The attacker also maintains two credential dictionaries: one that combines data from previous data breaches and purchased datasets, and another with 16 specialized dictionaries targeting FortiGate admin accounts. The cracked credentials are then used for lateral movement, often through RDP, SMB, or SSH, and data is exfiltrated from network shares. The campaign has also been observed stealing Kerberos hashes, with a notable incident on June 15, 2024, where the attacker successfully cracked Kerberos hashes and exfiltrated DFS backup data from a defense contractor aligned with NATO.

Impact on Businesses and Supply Chains

The FortiBleed campaign heavily targets small and medium-sized businesses (SMBs) with fewer than 200 employees, though organizations of all sizes are affected. The geographic focus is on the United States and India, but victims span the globe. Because the attacker targets managed service providers (MSPs) and IT firms that manage Fortinet devices for multiple clients, the campaign has deep supply chain implications. A compromise at an MSP can expose dozens or hundreds of downstream customers, amplifying the impact.

The attacker's ability to harvest credentials from network traffic means that even if a company uses strong passwords, the attacker can capture them when they traverse the compromised firewall in cleartext. This is particularly dangerous for organizations that rely on single sign-on or legacy authentication protocols. The stolen credentials can also be reused across different systems, leading to broader breaches.

Given the financial motivation and potential ties to Russian state-sponsored groups, the campaign poses a significant threat to national security, especially for defense contractors and critical infrastructure operators. The NATO-aligned defense contractor compromise suggests that the IAB may collaborate with state actors or sell high-value access to them.

Mitigation and Defense Strategies

To protect against such campaigns, organizations should take several steps. First, ensure that all FortiGate firewalls are patched with the latest firmware and that default credentials are changed. Disable unnecessary management interfaces and limit SSH access to trusted IP addresses. Implement multi-factor authentication (MFA) for all administrative accounts and consider using certificate-based authentication instead of passwords.

Network monitoring tools should be configured to detect unusual traffic patterns, such as large volumes of packet capture traffic or unexpected SSH connections. Organizations should also conduct regular credential audits and use password managers to reduce the risk of reuse. For MSPs, it is critical to segment networks and implement strict access controls between management systems and client environments.

Security researchers recommend that defenders regularly review firewall logs for signs of compromise and employ threat intelligence feeds to identify indicators of compromise (IOCs) associated with FortiBleed. SOCRadar has published a detailed report with specific IOCs, including IP addresses, domain names, and hashes of the FortigateSniffer tool.

The FortiBleed campaign is a stark reminder of the evolving threat landscape, where IABs are increasingly sophisticated and well-funded. Organizations must adopt a proactive security posture, focusing on both perimeter defenses and internal monitoring, to detect and respond to such attacks before they lead to data theft or ransomware incidents.


Source: SecurityWeek News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy