Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
🇷🇺 RU1 malware familyExploits CVEs in the wild

SantaAd

Also known asSantaAd

SantaAd is a Russian-speaking initial access broker (IAB) active on the Exploit cybercrime forum and associated in reporting with the 2026 FortiBleed campaign. Multiple sources in the provided content link or trace the operation to the handle SantaAd, although Palo Alto Networks Unit 42’s attribution is explicitly noted as unconfirmed by other researchers. SantaAd publicly implied responsibility by advertising Fortinet-related access, referencing public FortiBleed reporting, and raising auction prices. The activity described is financially motivated and oriented toward resale of validated access rather than espionage. Reported targets included internet-facing Fortinet FortiGate devices at scale, with broader targeting of Synology NAS devices, Sophos firewalls, RDWeb portals, Citrix SSL-VPN, exposed RDP instances, and MS-SQL servers. Victim organizations spanned 194 countries, with many targets being companies with fewer than 200 employees; IT providers and managed service providers were also prioritized in some reporting because of downstream access value. Reported tactics and techniques included internet-wide scanning using Masscan, Shodan, and custom tooling; brute-force and dictionary attacks against administrative panels, SSL-VPN, SSH, and MSSQL; use of credentials from prior leaks; and exploitation of old or unpatched FortiGate vulnerabilities. In the FortiBleed reporting, compromised FortiGate devices were used to deploy a custom Go-based sniffer called FortigateSniffer, which abused the legitimate FortiOS command "diagnose sniffer packet" to capture traffic and steal plaintext passwords, NTLM hashes, Kerberos material, tickets, tokens, and session cookies. Captured authentication material was reportedly processed through distributed cracking infrastructure using Hashcat/Hashtopolis and rented GPUs, then validated and used for lateral movement, Active Directory reconnaissance, access to network shares, and maintenance of access via stolen session cookies. The content also describes operator tooling and workflow consistent with a mature access-brokering operation: dedicated brute-force infrastructure, separate cracking infrastructure, disposable Kali Linux virtual machines, custom scripts, OpenConnect/OpenFortiVPN, Impacket, and reported use of AI-assisted development tooling including Cursor and the CyberStrike framework. SantaAd’s forum activity reportedly included sales or auctions for thousands of Fortinet admin panels and large Fortinet credential datasets, including posts advertising 80,000 rows of Fortinet devices and an auction for nearly 7,000 Fortinet devices.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Software & Services
  • Commercial & Professional Services
  • Military

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
  • 🇮🇳 India

Where they're from

Attributed origin per open-source reporting.

  • RU
MITRE ATT&CK

Tradecraft

14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics19 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
3 techniques
T1078×3
Valid Accounts
T1133
External Remote Services
T1190
Exploit Public-Facing Application
TA0003
Persistence
2 techniques
T1078×3
Valid Accounts
T1133
External Remote Services
TA0004
Privilege Escalation
1 technique
T1078×3
Valid Accounts
TA0005
Stealth
1 technique
T1078×3
Valid Accounts
TA0006
Credential Access
6 techniques
T1003
OS Credential Dumping
T1040
Network Sniffing
T1110×3
Brute Force
T1110.002
Password Cracking
T1110.003
Password Spraying
T1212
Exploitation for Credential Access
T1558
Steal or Forge Kerberos Tickets
T1649
Steal or Forge Authentication Certificates
TA0007
Discovery
3 techniques
T1018
Remote System Discovery
T1040
Network Sniffing
T1046
Network Service Discovery
TA0011
Command and Control
1 technique
T1090
Proxy
ACTIVITY FEED

Recent activity

3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

xakepNews
Jun 25, 2026
В кампании FortiBleed использовался сниффер, специально созданный для FortiGate - Хакер

Русскоязычный брокер первоначального доступа, предположительно связанный с кампанией FortiBleed. Операторы массово сканировали интернет-доступные системы, брутфорсили административные панели, SSL-VPN и SSH, эксплуатировали старые уязвимости FortiGate, устанавливали кастомный сниффер FortigateSniffer и перехватывали учетные данные для последующего использования, перепродажи или передачи другим преступникам.

Read more
security affairsNews
Jun 24, 2026
FortiBleed: The Broker Who Turned 73,000 Firewalls Into a Product Catalog

Financially motivated initial access brokering operation focused on obtaining, validating, cataloging, and reselling Fortinet firewall and remote-access credentials at global scale, likely for resale to ransomware crews.

Read more
spycloud blogNews
Jun 19, 2026
FortiBleed: Analysis of a Global Access Broker Campaign

Likely financially motivated initial access broker activity tied to the FortiBleed credential harvesting campaign. The actor is associated with mass scanning and brute-forcing of Fortinet FortiGate VPNs and other edge services, then monetizing validated access by advertising it for sale on Exploit.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping14

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs3

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

SantaAd | Mallory