Groove gang leaks list of credentials of compromised Fortinet appliances
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-13379 | Unauthenticated Path Traversal in Fortinet FortiOS SSL VPN CVE-2018-13379 is a path traversal flaw (CWE-22) in the Fortinet FortiOS SSL VPN web portal that allows an unauthenticated attacker to download FortiOS system files via specially crafted HTTP resource requests. By traversing directories through crafted requests to the exposed web portal, the attacker can retrieve sensitive files, a technique publicly documented as yielding the SSL VPN session file containing usernames and passwords in plaintext. Any organization running the SSL VPN web portal on a FortiGate appliance is affected, and risk is highest where the portal is directly reachable from the internet. The flaw is confirmed in the wild: it was added to the CISA KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. No public PoC is listed in the provided data, but credential theft tied to this bug has been widely reused by threat actors. Do: Apply the patched FortiOS release per Fortinet's vendor advisory immediately, as this is a CISA KEV required action; if the fixed version is not known from this data, follow Fortinet's FG-IR-18-384 advisory for the correct upgrade path. Rotate SSL VPN credentials and review VPN access logs for path-traversal requests, since successful exploitation exposes plaintext session credentials, and restrict SSL VPN portal exposure to trusted sources where possible. | 9.8 | 100% | KEV ransomware |
| mass≈500,000 internet-exposed FortiOS SSL VPN portals (Fortinet cited ~480,000 affected devices) |
Full article272 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 08, 2021

Groove gang leaked online Fortinet credentials that could be used to breach networks of organizations using the compromised devices.
The financially motivated threat actor Groove has leaked online compromised credentials belonging to many organizations. The ransomware group has been active since August 2021 and implement a double extortion model like other gangs.
The threat actor leaked a list containing approximately 500,000 Fortinet VPN credentials that can allow threat actors to breach the networks of the organizations that use the compromised VPN appliances and perform malicious activities such as dropping a ransomware or stealing sensitive data.
The credentials were likely amassed by the threat actors over the last few months by exploiting the CVE-2018-13379 Path Traversal flaw in Fortinet FortiOS running on Fortigate appliances.
Groove representative is likely a threat actor that goes online with the moniker “SongBird” who is a former operator of the Babuk gang. He is also the admin of a recently launched underground service named RAMP that focuses on ransomware operations.
SongBird also created a post on the RAMP forum that includes a link to a file containing the Fortinet VPN accounts.
Organizations are recommended to contact the CERTs of their country in order to determine if they are using one of the compromised Fortinet appliances.
Researchers from threat intelligence firm Advanced Intel that analyzed the leaked data, published the geographical distribution of the Fortinet VPN SSL list which includes 74 countries. 2,959 out of 22,500 victims are US entities.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Groove gang)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/121985/cyber-crime/groove-gang-fortinet-leaks.html