Vulnerabilities

FortiBleed Campaign Targets FortiGate Devices

June 23, 2026 12:15 · 12 min read
FortiBleed Campaign Targets FortiGate Devices

Introduction to the FortiBleed Campaign

The FortiBleed campaign, a large-scale operation targeting Fortinet FortiGate devices, has been revealed by security firm SOCRadar. The campaign, which has been active since at least February 2026, has targeted over 430,000 FortiGate firewalls worldwide, using custom sniffers to harvest authentication secrets and steal credentials.

The Threat Actor's Tactics

The threat actor behind the FortiBleed campaign serves as an initial access broker (IAB), using various tactics such as credential stuffing, brute-force attacks, credential harvesting, and offline password cracking to obtain access to corporate networks. One of the key findings of the researchers is the alleged use of a Golang-based tool dubbed "FortigateSniffer," which abuses FortiOS's built-in diagnose sniffer packet functionality to capture authentication traffic traversing compromised FortiGate devices.

How FortigateSniffer Works

FortigateSniffer is designed to monitor traffic for credentials, password hashes, and authentication secrets from various protocols, including RADIUS, NTLM, Kerberos, and LDAP. The tool connects to FortiGate devices over SSH and launches the FortiOS diagnose sniffer packet command, which allows admins to inspect network traffic passing through a FortiGate firewall in real time.

The command was configured to monitor traffic for authentication protocols and remote access services, including Kerberos, LDAP, SMB, RADIUS, RDP, WinRM, Microsoft SQL Server, MySQL, PostgreSQL, SMTP, IMAP, POP3, FTP, and Telnet. The packet data collected from FortiGate devices was processed through a component named "SNIFTRAN," which reconstructed the captured traffic into PCAP files.

Extracting Credentials and Password Hashes

The captured data was then parsed through a Python-based "PCAP Deep Analysis Toolkit" that extracted cleartext credentials, password hashes, Kerberos tickets, NTLM authentication material, email credentials, database credentials, and other authentication artifacts from the network traffic. The toolkit generated Hashcat-ready files containing NTLM and Kerberos hashes, and extracted cleartext credentials from protocols such as SMTP, IMAP, POP3, MySQL, and RADIUS when available.

Cracking Password Hashes

The threat actors allegedly used the GPU-based Hashcat password cracking utility running on a distributed GPU cluster to crack the hashed credentials. According to cybersecurity expert Kevin Beaumont, the attackers also obtained hashed credentials by downloading FortiGate configuration files from compromised devices and extracted the hashed credentials using Hashcat and 36 enterprise-class GPUs.

Beaumont explains that "the password cracking was hosted at a GenAI company which rents GPU compute. The attacker rented 36 enterprise class GPUs — more than most large orgs have for internal AI efforts — and instead of using it for AI tasks, they used them for password cracking. Enterprise GPUs can crack passwords at scale very quickly."

Recommendations for Fortinet Device Managers

For those managing Fortinet devices, Beaumont has published the list of IP addresses targeted in this campaign. Organizations utilizing FortiGate devices should review this list and investigate whether any of their systems were targeted or compromised.

By taking these steps, organizations can help protect their FortiGate devices and prevent the theft of credentials and authentication secrets.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free