FortiBleed Credential Theft Campaign Tied to Lynx and INC Ransomware Groups

The FortiBleed credential theft campaign, which compromised more than 73,000 Fortinet devices, is now directly linked to the INC and Lynx ransomware-as-a-service groups. SOCRadar's Threat Research Unit discovers the connection after identifying a Windows server used as part of the FortiBleed infrastructure that contains access to ransomware negotiation panels for both groups.

The campaign deploys a custom packet-sniffing tool called "FortiGate Sniffer" on compromised firewalls, allowing attackers to intercept VPN credentials and authentication data directly from network traffic. Investigators find the operation uses over 200 operational servers to crack password hashes and perform credential-stuffing attacks on a massive scale.

SOCRadar uncovers evidence showing victim information harvested during FortiBleed overlaps with organizations later listed on the INC ransomware leak site, suggesting stolen credentials directly fuel downstream ransomware attacks. The findings indicate the threat actors leverage initial access from compromised Fortinet devices as a pipeline for ransomware operations.

Read More at the original source →