FortiBleed is a financially motivated initial access brokering and credential-harvesting operation targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways worldwide. The name also identifies the campaign conducted by its operators. It operates as a structured group with a small core of operators and approximately 20 participants. Its country of origin is not established. The operation scans exposed FortiGate services and uses credential stuffing and password spraying with credentials obtained from previous Fortinet leaks and infostealer logs. Operators deploy a Go-based credential sniffer on compromised firewalls and crack stolen password hashes using Hashcat and Hashtopolis on a distributed GPU backend. Automated tooling filters out honeypots, profiles victim organizations, and prioritizes targets according to revenue and network structure. Attackers establish persistence through additional administrative accounts and sometimes delete legitimate accounts or change their passwords, locking administrators out of affected devices. After obtaining access, FortiBleed operators compromise VPN connections, enumerate Active Directory, identify privileged accounts through password spraying, and progress to domain-controller access and domain-administrator compromise. They package working VPN configurations and target information for downstream ransomware actors, including INC Ransom, Lynx, and Payload. FortiBleed is distinct from these ransomware groups, although its access has enabled confirmed ransomware deployments. Exposure of its own backend infrastructure revealed internal credentials, victim-tracking records, logs, and operational documentation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An ongoing initial-access brokerage operation compromising internet-facing FortiGate firewalls and SSL VPN gateways, maintaining administrative access, and supplying verified credentials and VPN configurations to downstream ransomware actors. The content reports more than 86,644 compromised devices across 194 countries and describes some victims being locked out of their own firewalls.
An initial access broker operation targeting Fortinet FortiGate firewalls to harvest credentials, profile victims, broker access, and potentially enable downstream ransomware deployment. The group is also assessed to be exploiting a Nextcloud zero-day for initial compromise or access expansion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.