<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

FortiBleed Campaign Linked to Inc and Lynx Ransomware Gangs

FortiBleed campaign hits 12,000+ Fortinet devices, linked with ransomware gangs, exploiting Nextcloud zero-day. Urgent security alert.
Content Team

The threat actors behind FortiBleed — a massive credential-harvesting campaign targeting Fortinet FortiGate firewalls — are feeding stolen access to the Inc Ransom and Lynx ransomware gangs. SOCRadar researchers caught a single operator logged into both groups' ransom negotiation panels while using infrastructure tied directly to FortiBleed, though they assess FortiBleed runs as a separate outfit selling access rather than as a partner in either operation.

Of 430,000 FortiGate devices targeted globally, roughly 12,000 currently carry FortiBleed's Golang sniffer, which quietly turns the firewall itself into a credential harvester. Credentials have been stolen from over 30,000. Of 409 targets where attackers gained admin access, 354 saw the full chain executed — VPN breach, domain controller access, domain admin.

At least 12 ransomware deployments have been confirmed, encrypting hundreds of endpoints. SOCRadar also flagged an unpatched Nextcloud zero-day being actively exploited during FortiBleed's access-brokering stage; Nextcloud says it has had no formal report and has promised a fast fix.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo