SantaAd
SantaAd is a Russian-speaking initial access broker (IAB) active on the Exploit cybercrime forum and associated in reporting with the 2026 FortiBleed campaign. Multiple sources in the provided content link or trace the operation to the handle SantaAd, although Palo Alto Networks Unit 42’s attribution is explicitly noted as unconfirmed by other researchers. SantaAd publicly implied responsibility by advertising Fortinet-related access, referencing public FortiBleed reporting, and raising auction prices. The activity described is financially motivated and oriented toward resale of validated access rather than espionage. Reported targets included internet-facing Fortinet FortiGate devices at scale, with broader targeting of Synology NAS devices, Sophos firewalls, RDWeb portals, Citrix SSL-VPN, exposed RDP instances, and MS-SQL servers. Victim organizations spanned 194 countries, with many targets being companies with fewer than 200 employees; IT providers and managed service providers were also prioritized in some reporting because of downstream access value. Reported tactics and techniques included internet-wide scanning using Masscan, Shodan, and custom tooling; brute-force and dictionary attacks against administrative panels, SSL-VPN, SSH, and MSSQL; use of credentials from prior leaks; and exploitation of old or unpatched FortiGate vulnerabilities. In the FortiBleed reporting, compromised FortiGate devices were used to deploy a custom Go-based sniffer called FortigateSniffer, which abused the legitimate FortiOS command "diagnose sniffer packet" to capture traffic and steal plaintext passwords, NTLM hashes, Kerberos material, tickets, tokens, and session cookies. Captured authentication material was reportedly processed through distributed cracking infrastructure using Hashcat/Hashtopolis and rented GPUs, then validated and used for lateral movement, Active Directory reconnaissance, access to network shares, and maintenance of access via stolen session cookies. The content also describes operator tooling and workflow consistent with a mature access-brokering operation: dedicated brute-force infrastructure, separate cracking infrastructure, disposable Kali Linux virtual machines, custom scripts, OpenConnect/OpenFortiVPN, Impacket, and reported use of AI-assisted development tooling including Cursor and the CyberStrike framework. SantaAd’s forum activity reportedly included sales or auctions for thousands of Fortinet admin panels and large Fortinet credential datasets, including posts advertising 80,000 rows of Fortinet devices and an auction for nearly 7,000 Fortinet devices.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Software & Services
- Commercial & Professional Services
- Military
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇮🇳 India
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Associated vulnerabilities
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Представители Fortinet допускали, что в кампании могли использоваться уязвимости CVE-2026-24858, CVE-2025-59718 и CVE-2025-59719.
Представители Fortinet допускали, что в кампании могли использоваться уязвимости CVE-2026-24858, CVE-2025-59718 и CVE-2025-59719.
Представители Fortinet допускали, что в кампании могли использоваться уязвимости CVE-2026-24858, CVE-2025-59718 и CVE-2025-59719.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Русскоязычный брокер первоначального доступа, предположительно связанный с кампанией FortiBleed. Операторы массово сканировали интернет-доступные системы, брутфорсили административные панели, SSL-VPN и SSH, эксплуатировали старые уязвимости FortiGate, устанавливали кастомный сниффер FortigateSniffer и перехватывали учетные данные для последующего использования, перепродажи или передачи другим преступникам.
Financially motivated initial access brokering operation focused on obtaining, validating, cataloging, and reselling Fortinet firewall and remote-access credentials at global scale, likely for resale to ransomware crews.
Likely financially motivated initial access broker activity tied to the FortiBleed credential harvesting campaign. The actor is associated with mass scanning and brute-forcing of Fortinet FortiGate VPNs and other edge services, then monetizing validated access by advertising it for sale on Exploit.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.