FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
FortiBleed, a massive credential-harvesting operation that has targeted more than 430,000 FortiGate firewalls worldwide, is thought to be the work of a Russian-speaking initial access broker (IAB) motivated by financial gain.
The campaign, which has been running since February 2026, entails gathering lists of credentials, looking for services that are vulnerable, brute-forcing systems that are accessible, and installing custom sniffers on firewalls that have been infiltrated.
Once installed, these sniffers extract hashed credentials and cleartext from traffic flowing via infected devices, according to a recent analysis by SOCRadar [PDF]. The credentials are then cracked, verified, and reused by the actors against exposed services and Active Directory domains.
A Golang-based progr...

