FortiBleed Campaign Exploits FortiGate Firewalls
A widespread threat campaign dubbed FortiBleed is actively compromising Fortinet FortiGate firewalls to steal sensitive authentication credentials. Security researchers at SOCRadar have detailed how attackers deploy custom-built sniffing tools directly onto the compromised devices. These sniffers intercept and harvest authentication secrets, providing attackers with access to internal networks and sensitive data.
The campaign’s primary objective appears to be gaining persistent access to enterprise networks by exploiting vulnerabilities in FortiGate devices. Once a firewall is compromised, the attackers install a sophisticated sniffer. This tool is designed to capture network traffic specifically containing authentication data, such as usernames and passwords, as they are transmitted or stored by the firewall.
The scale of the FortiBleed campaign suggests a well-resourced and organized threat actor. The use of custom tooling indicates a deliberate effort to evade detection and maximize the effectiveness of their attacks. By targeting network perimeter devices like FortiGate firewalls, attackers can gain a critical foothold into an organization’s infrastructure.

Custom Sniffer for Credential Harvesting
The core of the FortiBleed campaign's technical prowess lies in its custom sniffer. Unlike generic network monitoring tools, this sniffer is tailored to identify and extract specific types of data relevant to authentication. This includes credentials used for VPN connections, administrative access, and potentially other internal services that the FortiGate firewall manages or provides access to.
Attackers likely exploit known or zero-day vulnerabilities in FortiOS, Fortinet's operating system for FortiGate devices, to gain initial access. Once inside, they elevate privileges and deploy the sniffer. The sniffer operates stealthily, monitoring network traffic flowing through the firewall. It is programmed to recognize patterns associated with authentication protocols, such as logins, session establishment, and credential exchanges.
The harvested credentials can then be exfiltrated to attacker-controlled infrastructure. This allows the threat actors to authenticate as legitimate users, bypassing traditional security measures and moving laterally within the compromised network. The ability to steal credentials directly from a trusted network device like a firewall is a significant threat, as it grants attackers a privileged vantage point.
The specific technical details of the sniffer remain under investigation, but its effectiveness highlights the risks associated with sophisticated, custom malware. Generic security solutions might struggle to detect such tailored tools, which are designed to mimic legitimate system processes or blend into normal network traffic. The implications for organizations relying on FortiGate devices for their network security are substantial.

Impact and Mitigation Strategies
The FortiBleed campaign poses a severe risk to organizations using vulnerable FortiGate devices. Stolen credentials can lead to unauthorized access, data breaches, ransomware attacks, and further compromise of internal systems. The compromised firewalls, which are supposed to be a bastion of security, become the very entry point for attackers.
SOCRadar advises organizations to take immediate steps to secure their FortiGate devices. This includes ensuring all devices are running the latest stable firmware versions, which often include patches for exploited vulnerabilities. Regular security audits and network monitoring are crucial to detect any signs of compromise, such as unusual network traffic patterns or the presence of unauthorized files.
For organizations that suspect their FortiGate devices may have been compromised, immediate action is necessary. This involves isolating the affected device, performing a thorough forensic analysis to identify the extent of the compromise, and removing any malicious tools like the custom sniffer. All credentials that may have been exposed should be reset immediately, and multi-factor authentication (MFA) should be enforced wherever possible to add an extra layer of security.
The ongoing nature of the FortiBleed campaign underscores the importance of proactive security measures and rapid incident response. Threat actors are continuously developing new techniques to bypass security controls, making vigilance and up-to-date security practices paramount for protecting sensitive data and network infrastructure.
