FortigateSniffer is a Go-based credential-interception tool used in the FortiBleed campaign against compromised Fortinet FortiGate firewalls and SSL VPN gateways. Available in Linux and Windows builds, it connects to FortiGate devices over SSH after attackers obtain administrative access and abuses FortiOS’s native packet-sniffing diagnostic functionality to passively collect authentication traffic traversing the appliances. It monitors 24 protocols, including Kerberos, LDAP, SMB, RADIUS, RDP, WinRM, email, and database protocols. Its associated processing pipeline reconstructs captured traffic into packet captures and extracts cleartext usernames and passwords, NTLM authentication material, Kerberos hashes and tickets, session cookies, and other authentication artifacts. Geographic filtering and restricted execution windows limit collection activity.
FortigateSniffer is deployed after compromise rather than serving as the initial-access mechanism. FortiBleed operators obtain access through credential stuffing, password spraying, and brute-force attacks using leaked or reused credentials. Harvested authentication material is subsequently cracked using distributed GPU infrastructure, validated, and reused for internal reconnaissance, lateral movement, authenticated-session abuse, and theft from network shares. The campaign targets organizations globally, with substantial exposure among small and medium-sized businesses, IT service providers, managed service providers, and telecommunications organizations. FortiBleed-derived access has been linked to subsequent INC Ransom and Lynx ransomware deployments; FortigateSniffer itself is a credential-collection tool, not ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Однако в мае схема усложнилась, и на устройства начали устанавливать написанный на Go инструмент FortigateSniffer. Этот сниффер злоупотребляет штатной командой FortiOS diagnose sniffer packet, предназначенной для диагностики сети, и пассивно прослушивает проходящий через брандмауэр трафик сразу 24 протоколов.
Однако в мае схема усложнилась, и на устройства начали устанавливать написанный на Go инструмент FortigateSniffer. Этот сниффер злоупотребляет штатной командой FortiOS diagnose sniffer packet, предназначенной для диагностики сети, и пассивно прослушивает проходящий через брандмауэр трафик сразу 24 протоколов.
Однако в мае схема усложнилась, и на устройства начали устанавливать написанный на Go инструмент FortigateSniffer. Этот сниффер злоупотребляет штатной командой FortiOS diagnose sniffer packet, предназначенной для диагностики сети, и пассивно прослушивает проходящий через брандмауэр трафик сразу 24 протоколов.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Однако в мае схема усложнилась, и на устройства начали устанавливать написанный на Go инструмент FortigateSniffer. Этот сниффер злоупотребляет штатной командой FortiOS diagnose sniffer packet, предназначенной для диагностики сети, и пассивно прослушивает проходящий через брандмауэр трафик сразу 24 протоколов.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
STRU tracked scanning activity against roughly 11,250 FortiGate portals in more than 150 countries, with admin-level access confirmed on 409 targets.
STRU tracked scanning activity against roughly 11,250 FortiGate portals in more than 150 countries, with admin-level access confirmed on 409 targets.
STRU tracked scanning activity against roughly 11,250 FortiGate portals in more than 150 countries, with admin-level access confirmed on 409 targets.
Traffic Harvesting: After gaining SSH access, a custom FortiGate sniffer captures sensitive traffic and extracts credentials and authentication hashes.
Once access is obtained, a custom Golang-based credential-harvesting tool dubbed FortigateSniffer is deployed to passively capture credentials from traffic passing through the compromised device.
FortiBleed is a large-scale credential-harvesting campaign that has targeted more than 430,000 FortiGate firewalls worldwide, using a custom tool to passively intercept authentication traffic.
Session Hijacking: Uses session cookies and tokens captured by the sniffer to gain immediate authenticated access to internal applications without additional exploitation
MITRE ATT&CK Techniques ... Credential Access Network Sniffing Adversary-in-the-Middle T1040 T1557 Uses compromised FortiGate to capture login traffic passing through it across multiple services
Сниффер похищает пароли в открытом виде, NTLM- и Kerberos-хеши, тикеты, токены и другие аутентификационные данные.
Once sniffed, the raw SSH terminal output is converted into .pcapng format by the SNIFTRAN engine, then processed through a PCAP Deep Analysis Toolkit (v5.0) that extracts cleartext credentials, NTLMv2 hashes, Kerberos TGS/ASREP tickets, and session cookies.
Once successful credentials are recovered, they can be weaponized for lateral movement, Active Directory reconnaissance, Kerberos verification, SMB authentication, and further network expansion...
Once access is obtained, a custom Golang-based credential-harvesting tool dubbed FortigateSniffer is deployed to passively capture credentials from traffic passing through the compromised device.
A structured, multi-stage attack chain is employed in the attack chain, beginning with large-scale internet reconnaissance, which involves the use of scanning utilities and customized filtering tools for the detection and categorization of FortiGate systems by location.
Once successful credentials are recovered, they can be weaponized for lateral movement, Active Directory reconnaissance, Kerberos verification, SMB authentication, and further network expansion...
Using persistent SSH access, FortigateSniffer harvests authentication data while recovering hashed passwords are transferred to a dedicated cracking platform using distributed processing and automated task orchestration.
On 354 of those, the actor completed the full attack chain: VPN compromise, access to the domain controller, and domain admin.
Analysis showed that once FortiGate appliances were compromised, attackers deployed FortigateSniffer to covertly collect authentication traffic traversing the devices, allowing them to acquire both cleartext credentials and password hashes that were subsequently cracked, validated, and reused against Active Directory environments, VPN gateways, and other externally accessible enterprise services.
Once successful credentials are recovered, they can be weaponized for lateral movement... as well as obtaining sensitive information from file shares accessible to the attacker...
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based credential-harvesting tool deployed during the FortiBleed campaign against compromised Fortinet appliances. It passively intercepts authentication traffic across 24 protocols and collects credentials and password hashes for subsequent cracking and exploitation.
A Golang-based credential-harvesting sniffer deployed via SSH on compromised FortiGate devices. It abuses the FortiOS 'diagnose sniffer packet' command to capture authentication traffic across multiple protocols, enabling credential theft, session hijacking, and follow-on lateral movement.
Go-based sniffer deployed on compromised FortiGate devices to intercept firewall traffic and extract credentials, password hashes, and other sensitive information for follow-on intrusion activity.
A network sniffer deployed on FortiGate firewalls to intercept traffic and harvest cleartext credentials and password hashes for later compromise and persistent access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.