US cybersecurity authorities have urged administrators of Fortinet firewalls and gateways to harden their devices after revealing that the FortiBleed campaign is still ongoing.
A warning notice published by the FBI and US Secret Service on October 6 cited SOCRadar figures that FortiBleed has already compromised 86,644 devices across 194 countries.
The campaign targets Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. Ransomware affiliates from INC, Lynx and Payload groups are among those using the compromised credentials stolen in FortiBleed attacks for initial access, it claimed.
“Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials,” the notice read. “Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets.”
Read more on credential compromise: Researchers Track 2.9 Billion Compromised Credentials.
The campaign was first revealed back in June, after a security researcher discovered a trove of Fortinet usernames and plaintext passwords.
Hackers use automated tools to scan for exposed FortiGate SSL VPN portals, and then employ credential stuffing and password spraying techniques based on prior Fortinet leak dumps and infostealer logs to gain access.
Once they have found and exfiltrated additional credentials, they use a “GPU-accelerated cracking cluster” running Hashcat and Hashtopolis in order to decrypt the passwords into plaintext, the notice explained.
“Cracked credentials were enriched, sorted and validated, with scripts filtering out honeypots, mapping organizations and prioritizing high-value targets based on revenue and network structure. New administrative accounts were created on the firewall to maintain persistence,” the noticed continued.
“With verified credentials in hand, attackers moved into victim environments, conducting Active Directory enumeration and password spraying to expand access and identify privileged accounts.”
Incident Response and Mitigation Advice
The FBI/Secret Service notice urged organizations that detect potential compromise to:
- Isolate compromised hosts by quarantining or taking them offline
- Perform threat hunting to scope the intrusion
- Report the compromise to the FBI or Secret Service
- Use CISA’s Eviction Strategies Tool to evict the threat actor
- Harden the network by locking down management access
- Terminate admin/VPN sessions and reset credentials
- Enable phishing-resistant MFA
- Review firewall and VPN users and other configurations for unauthorized changes
- Review firewall, VPN, authentication, and domain controller logs for lateral movement
- Ensure secure credential storage using the PBKDF2 algorithm
John Strand, owner of Black Hills Information Security, said the most concerning thing about FortiBleed is the silent persistence it grants to threat actors.
“I’m not nearly as worried about an attacker who gets into an organization, locks everything down, and announces their presence,” he said. “I’m terrified of the attacker who wants to quietly live inside that organization for as long as possible. This attack gives them exactly that kind of access.”
