Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1577+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. FortiBleed Campaign Used Custom FortiGate Sniffer to Steal Credentials
FortiBleed Campaign Used Custom FortiGate Sniffer to Steal Credentials
NEWS

FortiBleed Campaign Used Custom FortiGate Sniffer to Steal Credentials

The large-scale FortiBleed campaign targeting Fortinet FortiGate devices deployed custom packet sniffers to harvest authentication secrets from compromised firewalls, systematically stealing credentials at scale.

Dylan H.

News Desk

June 22, 2026
3 min read

Security firm SOCRadar has published analysis revealing that the large-scale FortiBleed campaign targeting Fortinet FortiGate devices employed custom-built packet sniffers to systematically harvest authentication credentials from compromised firewalls. The sophisticated tooling allowed threat actors to silently intercept and exfiltrate authentication secrets at scale across thousands of affected devices.

Campaign Background

FortiBleed emerged as one of the most significant campaigns targeting Fortinet infrastructure, exploiting vulnerabilities in FortiGate devices to gain unauthorized access to enterprise firewalls. While initial reporting focused on the exploitation vector, the latest SOCRadar analysis reveals the full post-compromise toolchain used to maximize credential theft from breached devices.

Custom Sniffer Tooling

Rather than relying on generic credential dumping tools, the FortiBleed operators developed custom sniffers specifically engineered for the FortiGate environment. These tools were designed to:

  • Intercept authentication traffic passing through the firewall at the packet level
  • Parse FortiOS-specific session formats to extract credentials from administrative sessions, VPN authentications, and management plane communications
  • Operate stealthily within the FortiGate operating environment to avoid detection by standard endpoint security controls
  • Exfiltrate harvested credentials through covert channels that blend with normal firewall traffic patterns

The specialization of the sniffer code suggests the threat actors had significant prior knowledge of FortiGate internals — either through prior research, insider access to documentation, or extended access to test devices.

Scale of the Operation

The FortiBleed campaign affected a substantial number of FortiGate devices globally. By deploying credential sniffers on already-compromised devices, attackers could:

  • Harvest credentials for downstream networks connected through VPN tunnels
  • Collect administrative credentials for connected infrastructure managed through the FortiGate
  • Build lateral movement pathways into enterprise environments far beyond the initial compromise

This approach effectively turns each compromised FortiGate into a credential harvesting relay, amplifying the impact of the initial exploitation far beyond the firewall itself.

Fortinet's Response

Fortinet has released patches addressing the underlying vulnerabilities exploited by FortiBleed and has published indicators of compromise (IOCs) to assist organizations in determining whether their devices were part of the campaign. Organizations should reference Fortinet's PSIRT advisories for the full list of affected firmware versions.

Recommended Actions

Organizations running FortiGate devices should take the following steps:

  1. Apply all pending FortiOS patches — prioritize devices directly accessible from the internet
  2. Rotate all credentials that may have passed through FortiGate management interfaces, VPN endpoints, or policies during the potential compromise window
  3. Audit FortiGate logs for indicators of the custom sniffer tooling — look for unexpected processes or unusual filesystem activity
  4. Review VPN session logs for anomalous authentication patterns
  5. Check downstream systems for signs of lateral movement using credentials that may have been harvested
  6. Implement network segmentation to limit the blast radius of firewall-level compromises

Implications for Network Security

FortiBleed's use of custom sniffers at the firewall layer is particularly dangerous because network perimeter devices are typically trusted anchors — other security controls rarely monitor the firewall itself. When a firewall is compromised, it can become the most privileged vantage point in a network, with visibility into all traffic passing through it.

This campaign underscores the need to treat network appliances as part of the attack surface that requires monitoring, not just monitoring infrastructure. Organizations should deploy out-of-band management for critical network appliances and implement integrity monitoring to detect unauthorized modifications to firewall operating systems.

#Fortinet#FortiGate#Credential Theft#Threat Campaign

Related Articles

FortiBleed: Russian IAB Harvested 110 Million Credentials from 430,000 FortiGate Firewalls

A financially motivated Russian-speaking initial access broker behind the FortiBleed campaign has been systematically harvesting credentials from over 430,000 FortiGate firewalls worldwide since February 2026, amassing more than 110 million stolen credentials for sale on criminal markets.

5 min read

FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist

The FortiBleed campaign's operators weaponize Fortinet's own built-in diagnostic command to run a custom Golang sniffer that intercepts 24 authentication protocols — turning compromised FortiGate devices into self-sustaining credential harvesting platforms feeding 650+ parallel pipelines.

5 min read

FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices

A data leak dubbed FortiBleed has exposed configuration files and VPN credentials for 73,932 Fortinet firewall URLs, putting organizations worldwide at...

4 min read
Back to all News