Theregister FortiBleed Campaign Links Credential Theft to Ransomware Operations
Article Content
- •FortiBleed campaign linked to ransomware groups INC Ransom and Lynx.
- •Over 430,000 Fortinet firewalls targeted, with credentials harvested from 30,000 devices.
- •At least 12 ransomware deployments confirmed from FortiBleed access.
The FortiBleed campaign has been linked to two ransomware groups, INC Ransom and Lynx, through an operational security lapse that revealed one actor's simultaneous access to both groups' negotiation panels. This campaign targeted over 430,000 Fortinet firewalls, successfully harvesting credentials from at least 30,000 devices. Researchers confirmed admin-level access on 409 targets, with ransomware deployment occurring on 12 of those. The attack exploited SSL VPN authentication hashes, utilizing a 45-GPU cluster for cracking. The findings indicate that FortiBleed is not merely a credential theft operation but a precursor to ransomware attacks, significantly raising the stakes for organizations using FortiGate infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Inc Ransom in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Chinese Smishing Gang Targets Ireland and Four Other EU Countries Ireland is identified as one of five EU countries targeted by the Chinese text-scam group known as Smishing Triad, as reported by the EU cyber security agency Enisa. This group conducts large-scale smishing operations, which involve sending fraudulent text messages that impersonate legitimate organizations to steal…
Ransomhouse Targets Pertamina in Latest Ransomware Attack Ransomhouse has claimed a new victim, Pertamina, following the exposure of FortiOS SSL-VPN credentials due to the 'FortiBleed' vulnerability (CVE-2022-40684). This vulnerability was publicly disclosed on October 18, 2022, and has been actively exploited since October 11, 2022. The attack has led to the publication of…