FortiBleed Credential Theft Campaign Tied to INC and Lynx Ransomware Attacks

FortiBleed, the sprawling credential-harvesting campaign that has quietly compromised hundreds of thousands of FortiGate firewalls, now has a confirmed link to active ransomware operations.

SOCRadar’s Threat Research Unit (STRU) found an operator with access to FortiBleed’s infrastructure actively working negotiation panels for both INC Ransom and Lynx, connecting mass firewall credential theft to ransomware deployment for the first time.

STRU first documented FortiBleed as a large-scale credential-harvesting operation targeting more than 430,000 FortiGate firewalls worldwide.

FortiBleed Credential Theft Campaign

The threat actor operates as an Initial Access Broker, using a custom Golang tool called FortigateSniffer to passively intercept authentication traffic by abusing FortiOS’s native diagnose sniffer packet command across two dozen protocols.

The operation’s scale and financial motivation were clear from the start, though where the harvested access actually went remained an open question.

Continued mapping using Shodan, Censys, Validin, and internal IP block scanning revealed roughly 200 additional operational servers associated with the campaign.

Across this expanded infrastructure, STRU tracked scanning activity against roughly 11,250 FortiGate portals in more than 150 countries, with admin-level access confirmed on 409 targets.

On 354 of those, the actor completed the full attack chain, moving from VPN compromise to domain controller access and ultimately domain admin.

STRU has confirmed at least 12 ransomware deployments stemming from this access, with hundreds of endpoints encrypted across affected organizations.

An operational security lapse on one newly discovered server gave STRU visibility into the actor’s internal environment, forming the basis for the attribution that follows.

Inside that environment, STRU found an operator logged into negotiation panels for both INC Ransom and Lynx ransomware, engaging directly with ransom demands.

INC Ransom has operated since mid-2023 as a prolific RaaS group, while Lynx emerged roughly a year later and is widely assessed as an evolved INC variant.

A single operator working both panels, using FortiBleed-traceable infrastructure, provides the clearest evidence yet that FortiGate credentials harvested through this campaign are being handed off, or used directly, for ransomware deployment.

This is corroborated by victim overlap: comparing target data from FortiBleed’s own infrastructure against a separately discovered INC-linked open directory, STRU found matching victims across both datasets, independent confirmation that the same organizations were tracked by both operations.

STRU recovered an internal tracking document used to manage FortiGate targets, recording which credentials were used, which networks were accessed, and whether ransomware was ultimately deployed.

Analysis points to a structured operation of roughly 20 people, with a small core of primary operators driving high-impact intrusions, supported by dedicated specialists and a back-office layer of junior operators.

This investigation shows that FortiBleed isn’t an isolated operation sitting off to the side of the ransomware economy, it’s feeding directly into it.

The same access broker infrastructure that intercepted authentication traffic across hundreds of thousands of firewalls is connected, through a shared operator, to two active ransomware brands.

For organizations running FortiGate infrastructure, exposure to FortiBleed should now be treated as a potential precursor to ransomware.

SOCRadar’s forthcoming whitepaper will detail the complete infrastructure, the group’s organizational structure, operator tooling, and full indicators of compromise, along with a separate investigation into the group’s use of AI tooling toward at least one undisclosed zero-day currently under responsible disclosure.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories