threat-intel
Russian Initial Access Broker Behind FortiBleed Campaign
High
Summary
A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls globally as part of the FortiBleed campaign, harvesting credentials and selling access to other malicious actors. The campaign utilizes a custom Golang tool, FortigateSniffer, to capture authentication traffic and has resulted in the compromise of over 110 million credentials. This operation highlights the vulnerability of network edge devices and the potential for supply chain attacks.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data