FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware Activity
Summary
Hide ▲
Show ▼
FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing functionality, including `-diagnose sniffer packet`, to capture authentication traffic and recover credentials, password hashes, and session material across protocols such as RADIUS, NTLM, Kerberos, and LDAP. The activity is tied to a campaign active since at least February 2026 that targets over 430,000 FortiGate firewalls worldwide.
Related Happenings
FortiBleed multi-vendor brute-force wave
Exploitation Wave
H score75
First: 23.06.2026 21:20
Last: 23.06.2026 21:20
Sources 1
How related:
Perhaps the most interesting finding is that FortiBleed appears to be part of a broader, multi-vendor initial access operation that's orchestrated to not only target Fortinet devices, but also breach Synology NAS, Sophos firewalls, RDWeb portals, Citrix SSL-VPNs, and MS-SQL servers using automated brute-forcing since February 28, 2026.
About this happening:
A multi-vendor brute-force wave tied to FortiBleed is hitting Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL targets, expanding the risk from one firewall-focus...
FortiBleed multi-vendor brute-force wave
Exploitation WaveHow related: Perhaps the most interesting finding is that FortiBleed appears to be part of a broader, multi-vendor initial access operation that's orchestrated to not only target Fortinet devices, but also breach Synology NAS, Sophos firewalls, RDWeb portals, Citrix SSL-VPNs, and MS-SQL servers using automated brute-forcing since February 28, 2026.
About this happening: A multi-vendor brute-force wave tied to FortiBleed is hitting Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL targets, expanding the risk from one firewall-focus...
Initial access broker (IAB) campaign expands across multiple victims
Campaign
H score89
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
How related:
A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls as part of the FortiBleed credential-harvesting campaign, SOCRadar reports.
About this happening:
The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Initial access broker (IAB) campaign expands across multiple victims
CampaignHow related: A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls as part of the FortiBleed credential-harvesting campaign, SOCRadar reports.
About this happening: The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Latest development: 23.06.2026 13:30
On June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.
CISA warning on FortiBleed for FortiGate customers
Public Sector Action
H score89
First: 19.06.2026 17:00
Last: 19.06.2026 17:00
Sources 1
About this happening:
CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
CISA warning on FortiBleed for FortiGate customers
Public Sector ActionAbout this happening: CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
CISA FortiBleed mitigation guidance
Advisory/Mitigation
H score67
First: 19.06.2026 09:47
Last: 19.06.2026 09:47
Sources 1
About this happening:
CISA issued mitigation guidance for FortiBleed, urging operators of internet-accessible Fortinet devices to harden exposed FortiGate and VPN environments after a *...
CISA FortiBleed mitigation guidance
Advisory/MitigationAbout this happening: CISA issued mitigation guidance for FortiBleed, urging operators of internet-accessible Fortinet devices to harden exposed FortiGate and VPN environments after a *...
FortiBleed Fortinet/FortiGate VPN credential leak
Data Leak
H score80
First: 17.06.2026 18:12
Last: 17.06.2026 18:12
Sources 1
About this happening:
FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
FortiBleed Fortinet/FortiGate VPN credential leak
Data LeakAbout this happening: FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
Latest development: 19.06.2026 09:47
CISA urged Fortinet customers to secure FortiGate appliances after nearly 74,000 firewall and VPN credentials were exposed in the FortiBleed leak. The agency advised affected owners to terminate SSL VPN and administrative sessions, reset VPN and administrative passwords, enable phishing-resistant multifactor authentication, review logs for unauthorized access or lateral movement, store admin credentials with PBKDF2, restrict firewall management interfaces from public internet access, and remove unauthorized accounts.
Timeline
-
22.06.2026 23:01 4 articles · 23d ago
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Initial DisclosureA Golang-based FortigateSniffer deployment began on compromised FortiGate devices after administrative access was obtained. It launched FortiOS packet sniffing to monitor authentication flows and collect credentials.
Show sources
- FortiBleed campaign used custom FortiGate sniffer to steal credentials — www.bleepingcomputer.com — 22.06.2026 23:01
- FortiBleed campaign used custom FortiGate sniffer to steal credentials — www.bleepingcomputer.com — 22.06.2026 23:01
- Russian Initial Access Broker Behind FortiBleed Campaign — www.securityweek.com — 23.06.2026 13:30
- FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation — thehackernews.com — 23.06.2026 21:20