FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away
FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away 2026-10-7 13:49:39 Author: securityaffairs.com(查看原文) 阅读量:4 收藏

FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away

FBI and Secret Service warn FortiBleed, a credential-harvesting campaign against Fortinet firewalls, has compromised 86,644 devices and is locking out admins.

The FBI and the U.S. Secret Service issued a joint advisory about FortiBleed, and the headline number alone is worth sitting with: more than 86,644 compromised Fortinet FortiGate devices across 194 countries, according to SOCRadar’s verification. This isn’t a new zero-day. It’s something arguably more uncomfortable, a campaign built entirely on credentials that were already out there, reused, leaked, or sitting behind weak hashing nobody got around to replacing.

What makes this advisory different from a typical IOC list is how much it reveals about the attackers themselves. The operators behind FortiBleed accidentally exposed their backend infrastructure through an open directory, allowing investigators to see how the operation worked from the inside: how targets were selected, how stolen credentials were checked, and how access was prepared for sale. It is a rare case of attackers exposing themselves because of poor operational security.

“Threat actors use a combination of Internet Protocol (IP) addresses for their infrastructure to include their Command and Control (C2) servers, Relay Nodes, performing scanning activities, and using Hashtopolis. IP address 45.154.12[.]132 was seen in instances as a C2 server, with IP addresses 154.202.59[.]169 and 103.27.186[.]156 as proxy nodes used by the threat actors to obfuscate their presence, and 45.155.250[.]158 as a beacon relay.” reads the advisory.

The attack chain starts with automated scanning across the internet for exposed FortiGate SSL VPN portals, then moves into credential stuffing and password spraying using material pulled from prior Fortinet leak dumps and infostealer logs. Whatever hashes get harvested from there don’t get cracked by hand, they get fed into a GPU-accelerated cluster running Hashcat and Hashtopolis, turning stolen hashes into usable plaintext passwords at a scale no single attacker typing commands could match.

Once the stolen credentials are confirmed to work, the operation becomes more than simple credential theft. The attackers enrich and sort the accounts, remove honeypots, and prioritize targets based on revenue and network structure. It looks more like a sales process than a typical hacking operation.

They also create new admin accounts on the firewall to maintain access. From there, they move through the network, map Active Directory, and use password spraying to find accounts with higher privileges.

The part that should worry defenders most isn’t the breach itself, it’s what happens after. Threat actors have been deleting or changing passwords on existing accounts, which means some victim organizations are finding themselves completely locked out of their own Fortinet devices, unable to even start remediation without extra recovery steps beyond a normal patch-and-reset.

“Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system [T1531]. During the initial intrusion, threat actors create new accounts not previously on the device.” states the advisory. “In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment.”

There’s also a downstream consequence worth taking seriously if ransomware is anywhere on your threat model. The advisory confirms that access gained through FortiBleed has been sold onward to initial access brokers supplying ransomware affiliates, specifically naming INC/Lynx and Payload ransomware as currently active buyers. In other words, a credential-stuffing campaign against your firewall today can turn into an encrypted network tomorrow, with someone else entirely doing the encrypting.

The mitigation advice sounds like basic security hygiene that still needs to be repeated in 2026. Restrict external management access to trusted systems or use a local-in policy. Better still, remove internet-facing administration completely. End all active admin and VPN sessions, reset passwords on internet-facing systems, and require phishing-resistant MFA for every remote access and admin account.

One technical detail deserves more attention: the use of legacy SHA-256 password storage made large-scale password cracking much easier. Fortinet recommends using PBKDF2 for administrator passwords on FortiOS 7.2.11 and later. If your organization has not checked which password hashing method it uses, FortiBleed is a costly way to discover the problem.

The IP addresses and compromised account names published in the advisory, things like admin, fortiAdmin, and itadmin, aren’t meant to be blocked blindly. The authoring agencies specifically recommend vetting indicators before acting on them, since infrastructure on cloud platforms gets reassigned constantly, and what looks malicious today might be hosting something entirely innocent by next week.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, FortiBleed)




文章来源: https://securityaffairs.com/200558/cyber-crime/fortibleed-hit-86000-firewalls-by-exploiting-something-nobody-can-patch-away.html
如有侵权请联系:admin#unsafe.sh