A Russian-speaking initial access broker (IAB) has been linked to a large-scale credential-harvesting operation dubbed FortiBleed, targeting over 430,000 FortiGate firewalls globally since February 2026. The campaign, driven by financial gain, involves collecting credential lists, brute-forcing accessible systems, and deploying bespoke sniffers on compromised devices to capture cleartext and hashed credentials from traffic. Central to the operation is a Golang-based tool called FortigateSniffer, which leverages FortiOS diagnostic commands to passively intercept authentication data across 24 protocols, including TACACS+, Kerberos, SMB, LDAP, and RADIUS.
The attackers are estimated to have launched over 659 credential-harvesting pipelines between May 31 and June 15, 2026, resulting in the identification of over 110 million credentials, including 14.8 million RADIUS credentials, 924,000 NTLM hashes, 130,000 Kerberos hashes, and 89 million MySQL authentication tokens. The operation spans five stages: reconnaissance using Masscan and Shodan, device compromise via credential stuffing, deployment of FortigateSniffer for passive sniffing, hash cracking with Hashcat and Hashtopolis orchestrated by a Telegram bot named HASHBOT, and data exfiltration from network shares. The campaign also targets Synology NAS, Sophos firewalls, RDWeb portals, Citrix SSL-VPNs, and MS-SQL servers, and does not exploit any zero-day vulnerabilities, instead relying on weak passwords and lack of MFA.
Security firms SOCRadar, SpyCloud, Arctic Wolf, CloudSEK, and ZenoX have provided detailed analyses, noting the use of an open-source framework called CyberStrike for parts of the workflow. Affected organizations are advised to rotate credentials, invalidate sessions, audit configuration exports, and review SSL-VPN logins and AD/SMB activity.
CVEs: CVE-2026-11645
Attack groups: Russian-speaking initial access broker (IAB), SantaAd
Malware: FortigateSniffer, CyberStrike Harvester v1.5, FortiProbe-fast, GeoSplit, forticheck, harvest_orig, Hashcat, Hashtopolis, HASHBOT
Companies: SOCRadar, SpyCloud, Arctic Wolf, CloudSEK, ZenoX, Fortinet, Amazon
Products: FortiGate, FortiOS, Synology NAS, Sophos firewalls, RDWeb, Citrix SSL-VPN, MS-SQL, Masscan, Shodan, CyberStrike, CyberStrikeAI, Impacket
Original source: thehackernews.com