Infostealers
FortiBleed Campaign: AI-Driven Exploitation of Fortinet Firewalls
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The FortiBleed campaign exposed valid credentials for nearly 75,000 Fortinet FortiGate firewalls across 21,632 domains. Threat actors leveraged commoditized supercomputing resources to execute massive cryptographic attacks, previously the domain of state intelligence agencies. By renting a 36-GPU cluster from Vast.ai, they efficiently cracked passwords from harvested encrypted configuration files. The attackers utilized AI-assisted tools for managing their operations, including code editors and penetration testing frameworks. This incident highlights a significant shift in cybercrime, where financial motivation and advanced technology allow attackers to bypass traditional security measures. The impact is extensive, affecting numerous enterprises relying on Fortinet devices. The campaign underscores the need for enhanced security protocols to defend against such sophisticated threats.
Key Points: • FortiBleed compromised 75,000 Fortinet firewalls, affecting 21,632 domains. • Attackers utilized a 36-GPU cluster rented from Vast.ai for password cracking. • AI tools were employed for managing operations and automating penetration testing.