FortiBleed Credential Harvest Is Directly Feeding INC and Lynx Ransomware Operations
The FortiBleed campaign, which has been quietly hoovering up credentials from FortiGate firewalls across 150 countries, has now been directly tied to ransomware deployments by the INC Ransom and Lynx groups. That's according to threat intelligence firm SOCRadar, which stumbled into the operation's internals thanks to an operational security blunder by the attackers themselves.
FortiBleed first surfaced in mid-June, though it appears to have been running since at least February. The campaign targets FortiGate firewalls, planting a network sniffer called FortigateSniffer to intercept traffic and pull out cleartext credentials and password hashes. Over 430,000 devices were in the crosshairs. Estimated credential theft so far: north of 110 million.
SOCRadar's own scanning data shows roughly 11,250 FortiGate portals were probed, with 409 targets yielding administrative access. Of those, 354 saw the full attack chain executed: VPN compromise, domain controller access, domain admin privileges, the works. Twelve of those intrusions ended with ransomware being deployed, with hundreds of endpoints encrypted across the affected organisations.
The Russia-linked threat actor behind FortiBleed appears to be operating as an initial access broker, breaking in and either monetising access directly or handing it off. What makes this particularly interesting is SOCRadar caught a single operator logged into both the INC Ransom and Lynx negotiation panels. Cross-referencing that with victim overlap between FortiBleed targets and INC victims made the connection hard to argue with.
"Finding a single operator working both panels, using infrastructure traceable back to FortiBleed, is the clearest evidence yet that FortiGate credentials harvested through this campaign are being handed off, or used directly, for ransomware deployment," SOCRadar noted.
An internal tracking document recovered during their investigation suggests the operation involves around 20 people, split between those running high-impact intrusions and those handling the technical back-end.
INC Ransom has been one of the more active ransomware-as-a-service outfits since it appeared in mid-2023. Lynx came along roughly a year later and is widely considered a retooled version of the same codebase.
The broader takeaway here is straightforward and fairly grim. FortiBleed was never just a credential-theft side project. It was, and apparently still is, a supply chain for ransomware. The access broker model is maturing, and the pipeline from compromised firewall to encrypted endpoint is getting shorter.