

























A financially motivated threat actor has deployed a custom Golang-based tool called FortigateSniffer across more than 430,000 FortiGate firewalls globally, silently harvesting over 110 million credentials since at least February 2026, including confirmed data exfiltration from a NATO-aligned defense contractor.
The campaign, dubbed FortiBleed and investigated by SOCRadar’s Threat Research Unit (STRU), represents one of the most extensive credential-harvesting operations targeting network perimeter devices ever documented.
The threat actor, assessed to be an Initial Access Broker (IAB) motivated by financial gain, operated continuously through mid-June 2026, running 659 discrete harvest cycles with infrastructure that remains partially active at the time of writing. Tooling with Cyrillic-alphabet comments suggests a possible Russian origin, with potential links to ransomware groups or state-sponsored actors.
CISA has issued an urgent advisory warning organizations to secure their Fortinet devices following reports of a large-scale credential exposure.
The core weapon is FortigateSniffer (also tracked as fg_sniffer), a Golang-based tool compiled for both Linux (fg_sniffer_linux_amd64) and Windows (fg_sniffer_windows_amd64.exe). Its entire interface is in Russian.

Rather than deploying malware, the tool abuses FortiOS’s own built-in diagnostic command diagnose sniffer packet to passively intercept all authentication traffic traversing a compromised firewall across 24 protocols, including RADIUS, NTLM, Kerberos, LDAP, RDP, SMB, MSSQL, FTP, Telnet, and WinRM.
Once sniffed, the raw SSH terminal output is converted into .pcapng format by the SNIFTRAN engine, then processed through a PCAP Deep Analysis Toolkit (v5.0) that extracts cleartext credentials, NTLMv2 hashes, Kerberos TGS/ASREP tickets, and session cookies.
The tool also incorporates two evasion techniques: GeoIP-based filtering (using a binary-search-optimized ipgeo.csv) and business-hour scheduling, restricting active sniffing to 07:00–18:00 Moscow Time to minimize anomaly alerts during off-hours.
The operation follows a methodical, five-phase lifecycle:
match_corps.py, merge_revenue.py, build_report.py) then ranked targets by corporate revenue before any exploitation began — reflecting deliberate, economic-value-driven targeting rather than indiscriminate opportunism.gen_rotator generated host-credential Cartesian product combo files. These fed into mpbrute2.bin for SSH brute-force attacks against FortiGate admin accounts using 16 product-specific wordlists, and into forticheck (up to 25,000 threads) for SSLVPN portal credential stuffing.ssh.txt contained 237,330 working FortiGate SSH credentials.spray_da.py, smb_test.py, spider.py, and ad_full_audit.py then moved across Active Directory environments.backup_dfs.py recursively extracted full DFS shares via SMB and streamed them directly to attacker SSH servers without local staging. On June 15, 2026, following offline cracking of 172 Kerberos RC4 hashes, the actor executed a targeted DFS backup exfiltration against a NATO-aligned defense contractor.According to SOCRadar’s Threat Research Unit, the campaign exposed 23,406 unique domains across 80,553 FortiGate appliances. 66% of victims have fewer than 200 employees, with the 51–200 employee range accounting for 42.3% of all affected domains, organizations large enough to deploy FortiGate but typically lacking dedicated security operations.
IT services are the dominant sector (8.4% of victims), a deliberate targeting choice to maximize downstream access into customer environments. India (11.4%) and the United States (10.1%) top the geographic distribution, followed by Taiwan, Mexico, and Turkey.
| Category | Indicator |
|---|---|
| Aggregator / C2 | 85.11.187[.]8 |
| Pentest Lab Host | 193.8.187[.]2 |
| Credential Validation | 193.8.187[.]42 |
| Sniffer Node | 193.8.187[.]26 |
| Sniffer Node | 194.113.39[.]71 |
| Sniffer Node | 77.91.122[.]13 |
fg_sniffer_linux_amd64 SHA256 | 4d0b62d3162d4be391e3ba1e191dad28e5e5d5b161cfdef60eeb4361a92d8413 |
fg_sniffer_windows_amd64.exe SHA256 | 80d83eb01f28c87a61b51f1f83805e63a791905f019bd3b87f10a10f66efab1e |
mpbrute2.bin SHA256 | 2c98c86e6bd6f46cbd6c89d855541b9da91515b1bb986641a77e31c5c6aa2abb |
forticheck SHA256 | a8b09fd4f7ff2f298b45ca602992f44b3c2ac3746bcdb182c59ab2a20c690954 |
[.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.The campaign remains active as of mid-June 2026, with sniffer operations and harvestresults directories continuing to be updated.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。