FortiBleed Campaign Linked to Inc and Lynx Ransomware Gangs
Want more insights like this?
The threat actors behind FortiBleed — a massive credential-harvesting campaign targeting Fortinet FortiGate firewalls — are feeding stolen access to the Inc Ransom and Lynx ransomware gangs. SOCRadar researchers caught a single operator logged into both groups' ransom negotiation panels while using infrastructure tied directly to FortiBleed, though they assess FortiBleed runs as a separate outfit selling access rather than as a partner in either operation.
Of 430,000 FortiGate devices targeted globally, roughly 12,000 currently carry FortiBleed's Golang sniffer, which quietly turns the firewall itself into a credential harvester. Credentials have been stolen from over 30,000. Of 409 targets where attackers gained admin access, 354 saw the full chain executed — VPN breach, domain controller access, domain admin.
At least 12 ransomware deployments have been confirmed, encrypting hundreds of endpoints. SOCRadar also flagged an unpatched Nextcloud zero-day being actively exploited during FortiBleed's access-brokering stage; Nextcloud says it has had no formal report and has promised a fast fix.
Source: Dark Reading