OTX-6a358eb86925d602f0cf5600
info
📛 Threat Title
Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind
Description
An exposed attacker server has unveiled FortiBleed, a large-scale credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways globally. This operation involved credential harvesting through reuse, brute force, and hash cracking using a distributed GPU infrastructure with approximately 36 rented GPUs via Hashtopolis. The exposed directory contained 319 files revealing scanning tools, cracking infrastructure, credential databases, post-exploitation toolkits, and active VPN configurations. While initially reported as affecting 21,632 domains, analysis of the attacker's own tooling reveals only 918 organizations showed evidence of internal network compromise, with merely 148 confirmed cases where credentials were fully cracked. The operation ultimately aimed to sell initial access to compromised networks, with victims spanning 194 countries, predominantly India, United States, and Taiwan.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
-
OTX pulse
AlienVaulkt OTX
An exposed attacker server has unveiled FortiBleed, a large-scale credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways globally. This operation involved credential harvesting through reuse, brute force, and hash cracking using a distributed GPU infrastructure with approximately 36 rented GPUs via Hashtopolis. The exposed directory contained 319 files revealing scanning tools, cracking infrastructure, credential databases, post-exploitation to
- reference AlienVaulkt OTX
Remediations (8)
-
web:community.gurucul.com
Researchers uncovered the operation after threat actors accidentally exposed an open directory containing validated credentials, attack tooling, automation scripts, and operational logs. The findings provide rare insight into the attackers' infrastructure, revealing a coordinated effort to gain unauthorized access to Fortinet devices at scale.
-
web:gurucul.com
Intel Name: Inside the fortibleed open directory : a technical analysis of what the attacker left behind Date of Scan: June 22, 2026 Impact: High Summary: The exposure of operational infrastructure provides a rare, transparent view into modern cyberadversary methodologies. Recently, threat intelligence teams uncovered an exposed asset.
-
web:itnerd.blog
After several days spent reverse-engineering the attacker's environment, the SOCRadar research team has published a new, in-depth technical analysis on the FortiBleed campaign, including the attacker's infrastructure, tooling, and methods. Summary: FortiBleed is a large-scale, still-active credential-harvesting campaign targeting internet-facing Fortinet FortiGate firewalls — hundreds of ...
-
web:radar.offseq.com
Detailed information about Inside the FortiBleed Open Directory : A Technical Analysis of What the Attacker Left Behind . Get real-time updates, technical details
-
web:securitricks.com
Check the new attack report here : Inside the FortiBleed Open Directory : A Technical Analysis of What the Attacker Left Behind - credential harvesting, fortigate, vpn compromise, fortinet, initial access broker, 2026-06-19, fortibleed , hash cracking, hashtopolis
-
web:socradar.io
FortiBleed : SOCRadar's Investigation into 86,644 Compromised Fortinet Firewalls Dismantling FortiBleed : Inside an Active Fortinet Credential Harvesting Campaign What Is FortiBleed ? SOCRadar's Investigation Summary How FortiBleed Compromised Fortinet Firewalls: Intrusion Explained What Is the Root Cause of FortiBleed ? Who Is Behind FortiBleed ?
-
web:spycloud.com
The threat actor group behind " FortiBleed " was not just targeting FortiGate VPNs. By examining the infrastructure they used to launch the " FortiBleed " campaign over the course of the last month, we found that they were actually targeting a range of different internet-facing appliances with a standard spray-and-pray attack chain that ...
-
web:www.cloudsek.com
Inside the FortiBleed Open Directory : A Technical Analysis of What the Attacker Left Behind An exposed attacker server has revealed FortiBleed's complete operation—from credential harvesting and GPU-powered cracking to network intrusion and access sales.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.