A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx.
This finding provides the first confirmed evidence that mass theft of FortiGate credentials is being integrated into ransomware deployment processes, significantly increasing the threat posed by exposed firewall infrastructure.
FortiBleed Campaign Linked to INC and Lynx
Initially identified as a widespread credential-harvesting operation, FortiBleed targeted over 430,000 FortiGate firewalls worldwide using a custom Golang tool called “FortigateSniffer.”
This malware exploits FortiOS’s diagnostic packet capture functionality to intercept authentication traffic across various protocols, allowing attackers to collect valid credentials without triggering typical security alerts.
Operated by an initial access broker (IAB), the campaign appeared to be financially motivated. However, the specifics of its downstream use were unclear until now.
Further investigation by STRU expanded the known infrastructure footprint of FortiBleed, identifying more than 200 additional servers involved in scanning, sniffing, and exploitation activities.
Using internet-wide scanning platforms such as Shodan, Censys, and Validin, researchers observed active targeting of approximately 11,250 FortiGate portals across over 150 countries.
Of these, administrative access was successfully obtained in 409 instances, with 354 organisations experiencing full compromise chains, including VPN access, infiltration of domain controllers, and domain administrator privileges. At least 12 confirmed ransomware incidents have been attributed to this access, resulting in widespread endpoint encryption.
A critical breakthrough occurred בעקבות an operational security lapse, which exposed internal infrastructure used by the threat actors.
STRU analysts gained access to logs, internal documentation, and operational systems, revealing that a single operator associated with the FortiBleed campaign was simultaneously managing negotiation panels for both INC Ransom and Lynx ransomware groups.
This overlap provides strong attribution evidence linking the credential harvesting operation directly to ransomware deployment workflows.
Additional correlation was identified through victim overlap analysis. Data extracted from FortiBleed infrastructure was cross-referenced with an open directory associated with INC Ransom operations, revealing shared victim organizations across both datasets. This reinforces the conclusion that harvested FortiGate credentials are either sold to or directly utilized by ransomware affiliates.
The investigation also exposed the internal structure of the operation, highlighting a coordinated team of approximately 20 individuals.
The group appears to operate with a tiered model, including core intrusion specialists, infrastructure operators, and lower-level support personnel responsible for data handling and campaign management.
Internal tracking documents detailed credential usage, network access progression, and ransomware deployment status, indicating a mature and organized cybercriminal enterprise.
The findings underscore a critical shift in the threat landscape, where firewall-level credential harvesting is no longer an isolated activity but an integrated component of ransomware supply chains.
Organizations using FortiGate devices are now facing heightened risk, as credential exposure through campaigns like FortiBleed can rapidly escalate into full-scale ransomware incidents.
Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN





