threat-intel
FortiBleed campaign used custom FortiGate sniffer to steal credentials
Critical
Summary
The FortiBleed campaign, targeting Fortinet FortiGate devices, utilized a custom Golang tool called "FortigateSniffer" to steal credentials from compromised firewalls. This campaign, active since at least February 2026, involved over 430,000 devices and leveraged techniques like credential stuffing and brute-force attacks to gain initial access. The attackers then used the sniffer to capture authentication traffic, which was processed to extract credentials and cracked using a distributed GPU cluster.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data