FortiBleed Attack Campaign Exploiting Fortinet Firewalls and VPNs – FBI Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


The FBI and U.S. Secret Service have issued a joint cybersecurity advisory warning that the ongoing FortiBleed campaign is targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways worldwide.

The credential-compromise operation has reportedly affected more than 86,644 devices across 194 countries, creating a major risk for organizations that expose Fortinet management or remote-access services to the internet.

FortiBleed is not described as a single newly disclosed Fortinet vulnerability. Instead, attackers reportedly abuse reused, leaked, or weak credentials to access FortiGate appliances.

The campaign also exploits legacy SHA-256 password storage, allowing stolen authentication data to be processed through distributed password-cracking infrastructure.

Investigators said the operation became visible after its operators accidentally exposed a backend server containing tools, target data, and workflows.

FortiBleed Campaign Exploits

The exposed infrastructure reportedly showed an organized access-broker operation that scanned for publicly reachable FortiGate SSL VPN portals, tested stolen passwords, cracked password hashes, and verified accounts before selling working access to other cybercriminals.

The attackers allegedly used credential stuffing and password spraying to test credentials obtained from previous data leaks and infostealer logs.

After gaining entry, they may create new FortiGate administrator accounts to retain access. They can then enumerate Active Directory users, identify privileged accounts, and attempt lateral movement inside victim networks.

A key concern is that some affected organizations may lose access to their own Fortinet devices. The advisory said threat actors have changed passwords, disabled accounts, or deleted legitimate administrator accounts after creating their own persistent accounts.

FortiBleed MITRE ATT&CK Techniques :

Tactic Technique MITRE ID
Reconnaissance Active Scanning T1595
Initial Access Exploit Public-Facing Application T1190
Credential Access Password Spraying T1110.003
Credential Access Credential Stuffing T1110.004
Credential Access Credential Dumping T1003
Credential Access Password Cracking T1110.002
Persistence Create Local Account T1136.001
Defense Evasion / Initial Access Valid Accounts T1078
Discovery Account Discovery T1087
Exfiltration Exfiltration Over C2 Channel T1041
Impact Account Access Removal T1531

This tactic can delay incident response and leave defenders locked out while attackers continue operating in the environment. The FBI and USSS also warned that FortiBleed activity has been linked to initial-access brokers supporting ransomware operations.

Reported downstream ransomware connections include INC/Lynx and Payload ransomware, meaning a compromised firewall or VPN gateway could become the first stage of a larger enterprise-wide intrusion.

Organizations should immediately review all Fortinet administrative and VPN accounts, particularly unfamiliar accounts such as forticloud-sync, fgtsecure, forti_support2, or Technical_support.

Security teams should also investigate unexpected REST API keys, configuration changes, suspicious authentication activity, and connections involving known malicious infrastructure identified in the advisory.

The agencies recommend restricting external management access through trusted hosts or local-in policies, and removing internet-based administration where possible.

Administrators should terminate active administrative and VPN sessions, reset all Fortinet VPN and administrator credentials, and enforce phishing-resistant multifactor authentication for remote access and management interfaces.

Organizations running FortiOS should also verify that administrator credentials use PBKDF2 rather than weaker legacy hashing methods. Review firewall, VPN, authentication, and domain-controller logs to identify unauthorized accounts, successful suspicious logins, lateral movement, and attempts to alter device configurations.

Indicators of Compromise

IOC Type Indicator Key Detection Point
C2 45.154.12.132 Investigate firewall, VPN, proxy, and DNS connections.
Proxy 154.202.59.169, 103.27.186.156 Check for connections to attacker relay infrastructure.
Beacon Relay 45.155.250.158 Hunt HTTPS traffic on ports 4332 and 4432.
Password Cracking 85.11.187.8 Associated with FortiBleed password-cracking activity.
Related Infrastructure 193.8.187.2, 193.8.187.42 Linked to the FortiBleed attack chain.
Brute Force / Login Sources 104.28.155.27, 185.136.15.43, 185.136.15.66, 193.8.186.33, 45.227.254.210, 77.91.118.10, 80.75.212.113 Hunt for brute-force attempts and compromised logins.
Brute Force / Login Sources 87.251.64.13, .16, .17, .44, 66.175.220.111, 185.199.199.56 Check authentication activity and compromised accounts.
Suspicious Accounts forticloud-sync, forticloud-tech, fgtsecure, fgtsec, forti_support2, support_fortinet Check for unauthorized persistence accounts.
Network Behavior Ports 4332, 4432 Investigate unusual HTTPS traffic.
Device Changes New admin accounts, password changes, unknown API keys Review for persistence and unauthorized access.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post FortiBleed Attack Campaign Exploiting Fortinet Firewalls and VPNs – FBI Warns appeared first on Cyber Security News.