OTSecurity

FBI, Secret Service urge critical infrastructure operators to secure Fortinet gateways against FortiBleed attacks


The Federal Bureau of Investigation (FBI) and the U.S. Secret Service (USSS) warned that the FortiBleed credential-compromise campaign continues to target internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways, potentially locking organizations out of affected systems. The agencies identified that SOCRadar had verified more than 86,644 compromised devices across 194 countries. The campaign exploits reused or leaked credentials and legacy SHA-256 password storage to harvest and crack authentication data at scale, while attackers continue scanning exposed Fortinet firewalls using previously obtained credentials.

The advisory applies to all 16 critical infrastructure sectors, including energy, water and wastewater systems, healthcare and public health, communications, and transportation systems. Attackers use automated scanning, credential stuffing, and password spraying to find vulnerable systems and harvest authentication data, then crack stolen password hashes on a distributed graphics processing unit (GPU) cluster. Once credentials are validated, they create new administrative accounts, explore victim networks, and package the compromised access for sale to other threat actors.

The FBI and USSS warned that attackers may delete existing accounts or change passwords to prevent organizations from accessing affected devices, and said the attack chain has served as an initial entry point for ransomware affiliates, including INC/Lynx and Payload ransomware. Recommended measures include restricting external management access, terminating active administrative and VPN sessions, resetting credentials and enforcing phishing-resistant multifactor authentication.

FortiBleed is a credential-harvesting and access-broker operation whose internal workflow became visible only after the threat actors unintentionally exposed their backend server. Open directory revealed a mature, multi-stage campaign that targeted FortiGate SSL VPN appliances, harvested credentials at scale, and cracked them using a distributed graphics processing unit (GPU) cluster. The recovered tooling and datasets provide a rare, end-to-end view of how the operators identified targets, validated stolen credentials, and expanded access inside victim networks. 

The attackers began by scanning the internet for exposed FortiGate SSL VPN portals, using automated scripts to identify reachable devices and harvestable authentication surfaces. They then collected large volumes of credentials and authentication artifacts through credential stuffing and password spraying attacks, drawing on prior Fortinet leak dumps and infostealer logs. Password hashes obtained via credential dumping were exfiltrated and funneled into a GPU-accelerated cracking cluster for offline password cracking, where Hashcat and Hashtopolis orchestrated distributed jobs to convert the stolen data into usable plaintext credentials.

Once cracked, credentials were enriched, sorted, and validated, with scripts filtering out honeypots, mapping organizations, and prioritizing high-value targets based on revenue and network structure. The attackers also created new administrative accounts on the firewall to maintain persistence. With verified credentials in hand, they moved into victim environments, conducting Active Directory enumeration and further password spraying to expand access and identify privileged accounts. Also, operation culminated in the packaging and sale of that access, and the working VPN configurations and target lists indicate the group’s role as an initial-access broker supplying compromised networks to downstream threat actors.

“Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system,” the advisory detailed. “During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment.”

The agencies said that early responses revealed ongoing scanning activity against exposed Fortinet firewalls, with the threat actors relying on a network of servers to control their operations, relay traffic, hide their presence, and run their password-cracking tools. Several specific addresses were linked to these roles, including a command-and-control server, proxy nodes, and a beacon relay, and the actors typically communicated over standard encrypted web traffic. The authoring agencies caution that this infrastructure may sit on cloud platforms where addresses are reassigned, so the indicators should be treated as historical and checked against current network data before use.

After gaining initial access, the hackers created new accounts to maintain persistence and, in some cases, may have exploited SSH where the port was open on the firewall. Organizations are advised to review all Fortinet accounts and verify their legitimacy. Reporting also indicates that initial access brokers using the FortiBleed attack chain have passed access on to ransomware affiliates, currently including INC/Lynx and Payload.

If a potential compromise is detected, organizations should first determine which hosts were affected and isolate them by quarantining them or taking them offline. They should then begin threat hunting to scope the intrusion, collecting and reviewing relevant artifacts, logs, and other data to identify the threat actor’s tactics, techniques, and procedures (TTPs), the compromised devices and accounts, and a timeline of activity. The compromise should also be reported to the FBI, USSS, and other agencies as appropriate, using the contact information provided in the advisory.

Once enough threat hunting data has been collected to inform the choice of countermeasures, organizations should begin applying eviction measures to contain the incident and remove the threat actor from the network. This will likely overlap with ongoing threat hunting. 

CISA’s Eviction Strategies Tool can help here. It combines Playbook-NG, a web application, with COUN7ER, a database of post-compromise countermeasures mapped to adversary TTPs. Used together, they let organizations assemble a systematic eviction playbook with recommended response actions based on the threat actor’s TTPs, including each action’s intended outcome, preparatory steps, and associated risks. More detail is available in CISA’s Eviction Strategies Tool Fact Sheet. Finally, organizations should harden the network to prevent further malicious activity.

Because this attack chain can lead to lockouts and ransomware, the FBI and USSS urge all Fortinet customers with exposed gateways to review a set of defensive measures. Organizations should reduce their attack surface by restricting external device management, ideally by removing internet administration altogether, with trusted hosts and local-in policies as weaker alternatives. They should also terminate all active administrative and VPN sessions, reset all Fortinet VPN and administrative passwords, particularly on internet-facing systems, and enforce strong password policies. 

Additionally, organizations recognized that phishing-resistant multifactor authentication (MFA) should be required on all remote access and administrative accounts, and enforced on every external gateway and administrative interface. Organizations should also validate their firewall and VPN configurations, ideally by comparing them against a known-good baseline, and look closely for unrecognized accounts, using the list of compromised account names in the advisory as a guide. Firewall, VPN, authentication, and domain controller logs should be reviewed for lateral movement, unusual access, suspicious accounts, and unauthorized configuration changes, with the advisory’s list of IP addresses as a reference. 

The advisory also mentioned that administrator credentials should be stored using the Password-Based Key Derivation Function 2 (PBKDF2) algorithm, with weaker legacy hashes removed in line with Fortinet’s guidance for FortiOS v7.2.11 and later. Finally, the authoring organizations advise investigating and vetting indicators of compromise (IOCs) before acting on them, such as by blocking.



Source link