s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-6a358eb86925d602f0cf5600 info

📛 Threat Title

Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind

Category: vpn compromise Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

An exposed attacker server has unveiled FortiBleed, a large-scale credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways globally. This operation involved credential harvesting through reuse, brute force, and hash cracking using a distributed GPU infrastructure with approximately 36 rented GPUs via Hashtopolis. The exposed directory contained 319 files revealing scanning tools, cracking infrastructure, credential databases, post-exploitation toolkits, and active VPN configurations. While initially reported as affecting 21,632 domains, analysis of the attacker's own tooling reveals only 918 organizations showed evidence of internal network compromise, with merely 148 confirmed cases where credentials were fully cracked. The operation ultimately aimed to sell initial access to compromised networks, with victims spanning 194 countries, predominantly India, United States, and Taiwan.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (2)

  • OTX pulse AlienVaulkt OTX

    An exposed attacker server has unveiled FortiBleed, a large-scale credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways globally. This operation involved credential harvesting through reuse, brute force, and hash cracking using a distributed GPU infrastructure with approximately 36 rented GPUs via Hashtopolis. The exposed directory contained 319 files revealing scanning tools, cracking infrastructure, credential databases, post-exploitation to

  • reference AlienVaulkt OTX

Remediations (8)

  • web:community.gurucul.com

    Researchers uncovered the operation after threat actors accidentally exposed an open directory containing validated credentials, attack tooling, automation scripts, and operational logs. The findings provide rare insight into the attackers' infrastructure, revealing a coordinated effort to gain unauthorized access to Fortinet devices at scale.

  • web:gurucul.com

    Intel Name: Inside the fortibleed open directory : a technical analysis of what the attacker left behind Date of Scan: June 22, 2026 Impact: High Summary: The exposure of operational infrastructure provides a rare, transparent view into modern cyberadversary methodologies. Recently, threat intelligence teams uncovered an exposed asset.

  • web:itnerd.blog

    After several days spent reverse-engineering the attacker's environment, the SOCRadar research team has published a new, in-depth technical analysis on the FortiBleed campaign, including the attacker's infrastructure, tooling, and methods. Summary: FortiBleed is a large-scale, still-active credential-harvesting campaign targeting internet-facing Fortinet FortiGate firewalls — hundreds of ...

  • web:radar.offseq.com

    Detailed information about Inside the FortiBleed Open Directory : A Technical Analysis of What the Attacker Left Behind . Get real-time updates, technical details

  • web:securitricks.com

    Check the new attack report here : Inside the FortiBleed Open Directory : A Technical Analysis of What the Attacker Left Behind - credential harvesting, fortigate, vpn compromise, fortinet, initial access broker, 2026-06-19, fortibleed , hash cracking, hashtopolis

  • web:socradar.io

    FortiBleed : SOCRadar's Investigation into 86,644 Compromised Fortinet Firewalls Dismantling FortiBleed : Inside an Active Fortinet Credential Harvesting Campaign What Is FortiBleed ? SOCRadar's Investigation Summary How FortiBleed Compromised Fortinet Firewalls: Intrusion Explained What Is the Root Cause of FortiBleed ? Who Is Behind FortiBleed ?

  • web:spycloud.com

    The threat actor group behind " FortiBleed " was not just targeting FortiGate VPNs. By examining the infrastructure they used to launch the " FortiBleed " campaign over the course of the last month, we found that they were actually targeting a range of different internet-facing appliances with a standard spray-and-pray attack chain that ...

  • web:www.cloudsek.com

    Inside the FortiBleed Open Directory : A Technical Analysis of What the Attacker Left Behind An exposed attacker server has revealed FortiBleed's complete operation—from credential harvesting and GPU-powered cracking to network intrusion and access sales.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.