FBI and Secret Service Warn of FortiBleed Lockout Threat
FBI and Secret Service warn FortiBleed has compromised 86,644 Fortinet devices and can lock out administrators.
The FBI and US Secret Service warned on October 6 that the FortiBleed campaign is still compromising Fortinet FortiGate firewalls and SSL VPN gateways. Citing SOCRadar, the notice says 86,644 devices in 194 countries have already been compromised. Attackers scan exposed portals, then use credential stuffing and password spraying from earlier Fortinet leaks and infostealer logs, crack passwords with Hashcat and Hashtopolis, create new firewall admin accounts, and enumerate Active Directory. Ransomware affiliates from INC, Lynx, and Payload have used the stolen credentials, and victims can be locked out if accounts are disabled or passwords changed.
- FortiBleed has compromised 86,644 Fortinet devices across 194 countries.
- Attackers scan VPN portals and reuse leaked and infostealer credentials.
- They crack passwords, add firewall admins, and enumerate Active Directory.
- INC, Lynx, and Payload affiliates have used the stolen access.
Full article464 words · extracted from infosecurity-magazine.com · click to collapse
US cybersecurity authorities have urged administrators of Fortinet firewalls and gateways to harden their devices after revealing that the FortiBleed campaign is still ongoing.
A warning notice published by the FBI and US Secret Service on October 6 cited SOCRadar figures that FortiBleed has already compromised 86,644 devices across 194 countries.
The campaign targets Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. Ransomware affiliates from INC, Lynx and Payload groups are among those using the compromised credentials stolen in FortiBleed attacks for initial access, it claimed.
“Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials,” the notice read. “Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets.”
Read more on credential compromise: Researchers Track 2.9 Billion Compromised Credentials.
The campaign was first revealed back in June, after a security researcher discovered a trove of Fortinet usernames and plaintext passwords.
Hackers use automated tools to scan for exposed FortiGate SSL VPN portals, and then employ credential stuffing and password spraying techniques based on prior Fortinet leak dumps and infostealer logs to gain access.
Once they have found and exfiltrated additional credentials, they use a “GPU-accelerated cracking cluster” running Hashcat and Hashtopolis in order to decrypt the passwords into plaintext, the notice explained.
“Cracked credentials were enriched, sorted and validated, with scripts filtering out honeypots, mapping organizations and prioritizing high-value targets based on revenue and network structure. New administrative accounts were created on the firewall to maintain persistence,” the noticed continued.
“With verified credentials in hand, attackers moved into victim environments, conducting Active Directory enumeration and password spraying to expand access and identify privileged accounts.”
Incident Response and Mitigation Advice
The FBI/Secret Service notice urged organizations that detect potential compromise to:
- Isolate compromised hosts by quarantining or taking them offline
- Perform threat hunting to scope the intrusion
- Report the compromise to the FBI or Secret Service
- Use CISA’s Eviction Strategies Tool to evict the threat actor
- Harden the network by locking down management access
- Terminate admin/VPN sessions and reset credentials
- Enable phishing-resistant MFA
- Review firewall and VPN users and other configurations for unauthorized changes
- Review firewall, VPN, authentication, and domain controller logs for lateral movement
- Ensure secure credential storage using the PBKDF2 algorithm
John Strand, owner of Black Hills Information Security, said the most concerning thing about FortiBleed is the silent persistence it grants to threat actors.
“I’m not nearly as worried about an attacker who gets into an organization, locks everything down, and announces their presence,” he said. “I’m terrified of the attacker who wants to quietly live inside that organization for as long as possible. This attack gives them exactly that kind of access.”