started · updated
FortiBleed campaign harvests credentials from FortiGate firewalls worldwide
Security firm SOCRadar has detailed the ongoing FortiBleed operation, a large‑scale credential‑harvesting campaign that targets Fortinet FortiGate firewalls. The attackers have compromised more than 430,000 devices globally and, as of the report, are actively sniffing authentication traffic on over 19,000 firewalls, part of a broader pool of 80,553 identified targets.
The operation uses a custom Golang tool called **FortigateSniffer**, which abuses FortiOS’s built‑in *diagnose sniffer packet* command to capture credentials across 24 protocols, including RADIUS, NTLM, Kerberos and LDAP. Captured traffic is reconstructed with a component named **SNIFTRAN**, analyzed by a Python‑based PCAP toolkit, and the resulting hashes are cracked on a GPU cluster with Hashcat. The harvested credentials are sold as initial‑access broker services, allowing further ransomware or data‑extortion attacks. The campaign also conducts reconnaissance on other edge platforms such as Citrix and Sophos VPNs, though no compromised credentials for those have yet been confirmed.