FortiBleed: the massive theft of credentials that starts the Ransomware chain

Author: Published 4 min de lectura 220 reading

The images in this article were generated with artificial intelligence. How we publish

The recent exposure of the operation known as FortiBleed confirms something that response teams and cybersecurity intelligence feared: the mass of credentials stolen from FortiGate devices was not an end in itself but the first stage of a monetization chain that ends in ansomware. According to the analysis published by the intelligence firm, an operator connected to the FortiBleed infrastructure was directly involved in the negotiating panels of the INC and Lynx extortion groups, which linked the massive theft of administrative access to subsequent deployments of ciphers.

The operating mode described combines classic techniques and pernicious steps that are not visible: massive internet scanning to detect FortiGate exposed, attempts with known credentials combinations, and the installation of a go-written sniffer that collects credentials and tokens in transit. The reported scope is alarming: it is reported that the actor targeted about 430,000 firewalls, installed the sniffer on approximately 12,000 devices and collected more than 110 million credentials, with administrative access verified in hundreds of teams and at least 12 confirmed ransomware deployments.

FortiBleed: the massive theft of credentials that starts the Ransomware chain
Image generated with IA.

Beyond the numbers, there are two elements that aggravate the threat and that every security officer must consider. First, the operation seems organized and professional: internal documentation suggests a structure of about 20 people with separate roles (operators, specialists and support), which facilitates sustained and scalable operations. Second, the combination of initial access brokers that sell or facilitate access to ransomware bands reduces friction for destructive attacks; what could previously be a "mere" theft of information becomes operational interruption and extortion.

The campaign also led to an operational security error of the actor himself: a server with stolen credentials was exposed on the Internet, which allowed researchers to analyze files, records and tools. This leak is an opportunity for defenders: the artifacts found may contain compromise indicators (IoC) and behavior patterns that facilitate internal searches, blockages and proactive remediation.

In parallel, active holdings of a vulnerability have been reported in FortiClient EMS (reported by eSentire with respect to a case in the energy / utility sector), with the deployment of a credentials robber known as EKZ Stealer, who draws passwords from browsers and exfilters them via PowerShell. This other way illustrates a clear reality: attackers use multiple routes (exploits, sniffers, combinations of credentials) to achieve the same final objective: privileged credentials.

The practical implications for medium and large organisations are immediate. In the short term, it is essential to verify the integrity and configuration of any FortiGate or FortiClient device on its perimeter: update firmware and manufacturer patches, rotate administrative credentials, force the application of MFA for remote administrative access and audit recent access in management panels. It is also critical to look for evidence of unusual sniffers or binaries on the network route between customers and servers, and to review logs for atypical outgoing connections that could indicate exfiltration of credentials.

In operational terms, security teams should treat credentials as potentially compromised: renew pairs of keys and certificates when necessary, segment device management on separate networks with strict access controls, and centralize event log (IMS) to correlate access attempts, privileges elevations and lateral movement. If their organization is among the sectors identified as preferential by the attackers - manufacturing, technology and logistics in LATAM and APAC - these actions should be prioritized.

FortiBleed: the massive theft of credentials that starts the Ransomware chain
Image generated with IA.

In addition to technical measures, there are two organizational steps that often make a difference: to coordinate with the affected supplier to share findings and request official patches or mitigations, and to communicate the incident to authorities and intelligence exchange platforms to cut monetization channels. Research such as SOCRadar and eSentire notices offer useful context and sometimes IoC; compare them with their internal records and act quickly on coincidences.

To further and follow official recommendations, see both the public information of the firm that reported the campaign and the communications of the supplier concerned. More information on the SOCRadar site Socrates and on the eSentire portal eSentire, and contact the manufacturer for guides and patches through the security center of Fortinet Fortinet.

In short, FortiBleed is a reminder that exposed network infrastructures and reused credentials are a gold mine for the cybercrime economy. The good news is that many of the effective defenses are known and adopted: fast patching, credentials rotation, MFA, segmentation, continuous monitoring and coordination with suppliers and intelligence communities. Action on these practices today significantly reduces the risk of being the next victim of a chain that begins with the theft of an admin password and ends with organized ransomware operations.

Coverage

Related

More news on the same subject.