FBI Warns of Ongoing FortiBleed Attack Locking FortiGate VPN Administrators Out
The FBI is warning of an ongoing FortiBleed attack targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways. The attacks can lock legitimate administrators out of their devices and provide an entry point for ransomware operations.
Attackers access exposed endpoints using previously compromised credentials or login details obtained through infostealer logs, credential stuffing, and password-spraying attacks.
After compromising a device, the attackers extract additional authentication data and crack stolen password hashes offline using a distributed GPU cluster running Hashcat and Hashtopolis.
According to the FBI, “The FortiBleed attack chain has been observed as an initial point of entry for ransomware affiliates.” Groups benefiting from the campaign include the INC/Lynx and Payload ransomware operations.
FortiBleed credential leak continues to fuel attacks
FortiBleed is a large-scale Fortinet credential breach discovered in June. Attackers exposed servers containing usernames and cleartext passwords associated with 73,932 firewall URLs across 194 countries.
The exposed data revealed a widespread credential-harvesting operation, although the methods used to obtain the configuration data were initially unclear.
In July, SOCRadar linked FortiBleed to the INC and Lynx ransomware operations after accessing both groups’ negotiation panels on servers used in the campaign.
According to the latest count from SOCRadar, FortiBleed compromised 86,644 devices.
Attackers create accounts and lock out administrators
In some cases, attackers create new administrator accounts and use their privileges to delete existing administrator accounts or change passwords, denying victims access to their FortiGate devices, the FBI said.
The attackers then attempt to establish persistence and move laterally through the compromised environment.
Details of the operation emerged after the attackers accidentally exposed backend servers containing directories with tools and datasets.
The exposed infrastructure demonstrated the use of automated scripts that scan public FortiGate SSL VPN portals, a distributed GPU password-cracking setup, and scripts that validate credentials, filter honeypots, identify organizations, and prioritize targets based on revenue and network structure.
The exposure also revealed a working VPN configuration and target list, indicating that the operator was packaging compromised access for sale.
FBI recommends more than patching Fortinet devices
The FBI warned that remediation may require more than patching Fortinet devices and resetting passwords. Recommended steps include:
- Limiting external access to FortiGate administration interfaces and SSL VPN portals.
- Terminating all active VPN sessions.
- Enforcing multifactor authentication.
- Reviewing logs for unauthorized configuration changes and suspicious activity.
Organizations should also force PBKDF2 for storing administrator passwords. PBKDF2 is significantly stronger than traditional SHA-256 password hashes, which attackers can crack offline.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



