Friday, September 11, 2026

FortiBleed Campaign Linked to INC and Lynx Ransomware Operations

A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx.

This finding provides the first confirmed evidence that mass theft of FortiGate credentials is being integrated into ransomware deployment processes, significantly increasing the threat posed by exposed firewall infrastructure.

FortiBleed Campaign Linked to INC and Lynx

Initially identified as a widespread credential-harvesting operation, FortiBleed targeted over 430,000 FortiGate firewalls worldwide using a custom Golang tool called “FortigateSniffer.”

This malware exploits FortiOS’s diagnostic packet capture functionality to intercept authentication traffic across various protocols, allowing attackers to collect valid credentials without triggering typical security alerts.

Operated by an initial access broker (IAB), the campaign appeared to be financially motivated. However, the specifics of its downstream use were unclear until now.

Further investigation by STRU expanded the known infrastructure footprint of FortiBleed, identifying more than 200 additional servers involved in scanning, sniffing, and exploitation activities.

Using internet-wide scanning platforms such as Shodan, Censys, and Validin, researchers observed active targeting of approximately 11,250 FortiGate portals across over 150 countries.

Of these, administrative access was successfully obtained in 409 instances, with 354 organisations experiencing full compromise chains, including VPN access, infiltration of domain controllers, and domain administrator privileges. At least 12 confirmed ransomware incidents have been attributed to this access, resulting in widespread endpoint encryption.

A critical breakthrough occurred בעקבות an operational security lapse, which exposed internal infrastructure used by the threat actors.

STRU analysts gained access to logs, internal documentation, and operational systems, revealing that a single operator associated with the FortiBleed campaign was simultaneously managing negotiation panels for both INC Ransom and Lynx ransomware groups.

This overlap provides strong attribution evidence linking the credential harvesting operation directly to ransomware deployment workflows.

Additional correlation was identified through victim overlap analysis. Data extracted from FortiBleed infrastructure was cross-referenced with an open directory associated with INC Ransom operations, revealing shared victim organizations across both datasets. This reinforces the conclusion that harvested FortiGate credentials are either sold to or directly utilized by ransomware affiliates.

The investigation also exposed the internal structure of the operation, highlighting a coordinated team of approximately 20 individuals.

The group appears to operate with a tiered model, including core intrusion specialists, infrastructure operators, and lower-level support personnel responsible for data handling and campaign management.

Internal tracking documents detailed credential usage, network access progression, and ransomware deployment status, indicating a mature and organized cybercriminal enterprise.

The findings underscore a critical shift in the threat landscape, where firewall-level credential harvesting is no longer an isolated activity but an integrated component of ransomware supply chains.

Organizations using FortiGate devices are now facing heightened risk, as credential exposure through campaigns like FortiBleed can rapidly escalate into full-scale ransomware incidents.

Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News