← BACK TO FEED
ransomwareFortiGateINC Ransomcredential theftinitial access broker

FortiBleed Credential Harvest Is Directly Feeding INC and Lynx Ransomware Operations

The FortiBleed campaign, a large-scale credential-harvesting operation targeting over 430,000 FortiGate firewalls across 150 countries, has been directly linked to the deployment of INC Ransom and Lynx ransomware. Active since at least February and likely run by a Russian initial access broker involving around 20 individuals, the operation has compromised over 110 million credentials and resulted in ransomware attacks on 12 organisations, with hundreds of endpoints encrypted. SOCRadar confirmed the connection after an operational security mistake by the attackers exposed internal files, revealing a single operator working both ransomware negotiation panels using infrastructure tied to the FortiBleed campaign.

The FortiBleed campaign, which has been quietly hoovering up credentials from FortiGate firewalls across 150 countries, has now been directly tied to ransomware deployments by the INC Ransom and Lynx groups. That's according to threat intelligence firm SOCRadar, which stumbled into the operation's internals thanks to an operational security blunder by the attackers themselves.

FortiBleed first surfaced in mid-June, though it appears to have been running since at least February. The campaign targets FortiGate firewalls, planting a network sniffer called FortigateSniffer to intercept traffic and pull out cleartext credentials and password hashes. Over 430,000 devices were in the crosshairs. Estimated credential theft so far: north of 110 million.

SOCRadar's own scanning data shows roughly 11,250 FortiGate portals were probed, with 409 targets yielding administrative access. Of those, 354 saw the full attack chain executed: VPN compromise, domain controller access, domain admin privileges, the works. Twelve of those intrusions ended with ransomware being deployed, with hundreds of endpoints encrypted across the affected organisations.

The Russia-linked threat actor behind FortiBleed appears to be operating as an initial access broker, breaking in and either monetising access directly or handing it off. What makes this particularly interesting is SOCRadar caught a single operator logged into both the INC Ransom and Lynx negotiation panels. Cross-referencing that with victim overlap between FortiBleed targets and INC victims made the connection hard to argue with.

"Finding a single operator working both panels, using infrastructure traceable back to FortiBleed, is the clearest evidence yet that FortiGate credentials harvested through this campaign are being handed off, or used directly, for ransomware deployment," SOCRadar noted.

An internal tracking document recovered during their investigation suggests the operation involves around 20 people, split between those running high-impact intrusions and those handling the technical back-end.

INC Ransom has been one of the more active ransomware-as-a-service outfits since it appeared in mid-2023. Lynx came along roughly a year later and is widely considered a retooled version of the same codebase.

The broader takeaway here is straightforward and fairly grim. FortiBleed was never just a credential-theft side project. It was, and apparently still is, a supply chain for ransomware. The access broker model is maturing, and the pipeline from compromised firewall to encrypted endpoint is getting shorter.

READ NEXT
FortiBleed Gang Moonlights for INC and Lynx Ransomware as Credential Haul Reaches 110 MillionCitrix Bleed 2, Rogue Drivers, and Poisoned Packages: Ransomware Groups Are Getting CreativeAvalon Malware Framework Bundles Ransomware, Credential Theft and AI-Assisted Development Into One Nasty Package