
FortiBleed: a credential-harvesting and access-brokering campaign compromised roughly 73,000-86,000 internet-facing FortiGate firewalls, roughly 50% of all exposed devices, attributed to a Russian-speaking IAB group Unit 42 dubbed SantaAd. - FortiBleed is not a single CVE. It chains CVE-2018-13379 credential dumps, the Belsen Group's 15,000 FortiGate config-file leak, infostealer logs, and brute-forced password hashes into one industrial-scale operation. No malware touched FortiOS directly: attackers lived off the land using stolen and backdoor credentials plus the built-in FortiOS packet-sniffer command across 24 protocols. - FortiOS stored legacy AK1 (SHA-1) and SH2 (SHA-256) hashes alongside newer PBKDF2 hashes. When upgraded, the old hash was silently preserved in full config backups as an "old password" field for downgrade compatibility but hidden from a standard show config. Attackers rented 40-GPU Hashopolis clusters to crack those SHA-256 hashes at scale. - FortiGate Sniffer acted as an orchestrator: once one device was owned, attackers deployed passive sniffing to every device they accessed, collecting credentials from crossing traffic, not just FortiOS accounts. Victim metadata was enriched via SSL certificate org fields, then sorted by industry and revenue for IAB resale. - DFIR gap: network appliances sit outside EDR, and config-backup access requires super-admin credentials. #DFIR_Radar
Post summary
The report details an active credential‑harvesting campaign exploiting FortiGate devices, leveraging known CVEs and built‑in sniffer functionality to exfiltrate credentials at scale, with no de‑emphasis, PoC, or patch info provided.


