Actor Profile

FortiBleed is a campaign-level designation for coordinated activity targeting Fortinet FortiGate network security appliances. The campaign's primary objective is credential harvesting through the deployment of custom sniffers on compromised firewalls. The origin and attribution of the threat actor behind FortiBleed remain unclear from available data. The campaign demonstrates advanced understanding of FortiGate architecture and network security infrastructure, suggesting a sophisticated adversary with specific interest in enterprise network access and authentication data. The motivation appears to be intelligence gathering and establishing persistent access to enterprise networks through compromised perimeter security devices.

TTPs (Tactics, Techniques, Procedures)

The FortiBleed campaign employs custom credential sniffing tools deployed directly onto compromised Fortinet FortiGate devices. Key TTPs include: Initial Access via exploitation of FortiGate vulnerabilities (likely T1190: Exploit Public-Facing Application); Credential Access through network sniffing (T1040: Network Sniffing) to capture authentication credentials in transit; Collection of credentials from compromised network security appliances (T1552: Unsecured Credentials); and Persistence on network infrastructure devices. The use of custom sniffers indicates tailored tooling specifically designed for FortiGate environments, suggesting pre-operational reconnaissance and development efforts targeting this widely deployed platform.

Targets & Patterns

FortiBleed specifically targets organizations utilizing Fortinet FortiGate devices for network security and perimeter defense. Primary victims include enterprises across the Network Security and Enterprise Infrastructure sectors that rely on FortiGate firewalls as critical security controls. The campaign's focus on these devices is strategic: FortiGate appliances sit at network boundaries, process authentication traffic, and provide visibility into internal network communications. Compromising these devices enables adversaries to harvest credentials for VPN access, internal authentication, and administrative accounts. The large-scale nature of the campaign suggests opportunistic targeting of vulnerable FortiGate installations rather than highly selective victim profiling, though the sophistication indicates capability for follow-on operations against high-value targets.

Historical Context

The FortiBleed campaign represents part of a broader trend of threat actors targeting network infrastructure devices, particularly VPN and firewall appliances. This follows similar campaigns exploiting vulnerabilities in Fortinet products, including CVE-2022-42475 (authentication bypass) and CVE-2023-27997 (heap buffer overflow) that have been actively exploited by multiple threat actors. The focus on credential harvesting from network devices aligns with observed TTPs from Chinese APT groups and cybercrime actors seeking initial access to enterprise networks. The large-scale deployment of sniffers suggests this campaign may be related to or inspired by previous infrastructure-targeting operations that prioritize persistent access over immediate disruption.

Defensive Recommendations

  • Immediately audit all FortiGate devices for unauthorized processes, files, or configuration changes; review system logs for anomalous administrative access or command execution
  • Implement network segmentation to isolate FortiGate management interfaces from production networks; enforce multi-factor authentication for all administrative access to network security appliances
  • Deploy network monitoring to detect T1040 (Network Sniffing) by identifying unusual packet capture processes or unexpected network traffic patterns from FortiGate devices
  • Apply all available Fortinet security patches, particularly for CVE-2022-42475 and CVE-2023-27997; establish automated patch management for network infrastructure devices
  • Monitor for indicators of T1190 (Exploit Public-Facing Application) by analyzing FortiGate access logs for exploitation attempts, unusual authentication patterns, or connections from known malicious IP addresses