Actor Profile

INC and Lynx are ransomware threat actors linked to the FortiBleed credential theft campaign. These groups operate with the primary motivation of financial gain through ransomware deployment. The actors leverage stolen Fortinet credentials as an initial access vector to facilitate network intrusions, establishing a foothold for subsequent ransomware operations. The linkage between INC, Lynx, and the FortiBleed campaign suggests either coordinated activity between the groups or shared access to compromised credential databases, indicating a sophisticated operational model focused on pre-positioning access for future attacks.

TTPs (Tactics, Techniques, Procedures)

The primary TTP observed is credential theft targeting Fortinet infrastructure, likely exploiting vulnerabilities or misconfigurations in FortiGate devices (T1078 - Valid Accounts, T1133 - External Remote Services). The stolen credentials serve as initial access mechanisms for subsequent network intrusion and lateral movement. The ultimate objective is ransomware deployment (T1486 - Data Encrypted for Impact), with the credential harvesting phase representing pre-operational preparation. The campaign demonstrates a multi-stage attack methodology where credential theft operations are decoupled from immediate exploitation, allowing actors to maintain persistent access opportunities and select high-value targets for ransomware deployment.

Targets & Patterns

While specific targeted sectors are not identified in available data, the focus on Fortinet credentials indicates targeting of organizations utilizing FortiGate VPN and firewall solutions. These devices are commonly deployed across enterprise environments, suggesting broad targeting across multiple sectors. The strategic collection of credentials rather than immediate exploitation suggests the actors are building an access inventory for selective targeting based on victim value assessment. The ransomware operational model indicates preference for targets with significant financial resources and critical operational dependencies that increase likelihood of ransom payment.

Historical Context

The FortiBleed campaign represents an evolution in ransomware operational tradecraft, where initial access brokers or ransomware operators themselves conduct large-scale credential harvesting campaigns to build access repositories for future exploitation. This approach has been observed across the ransomware ecosystem, with groups increasingly investing in pre-positioning access before selecting victims for active intrusion. The linkage of multiple ransomware families (INC and Lynx) to the same credential theft campaign may indicate either a shared initial access broker relationship or overlapping operational infrastructure between the groups.

Defensive Recommendations

  • Implement multi-factor authentication (MFA) on all Fortinet VPN and remote access solutions to mitigate credential theft impact (T1078, T1133)
  • Monitor for anomalous authentication attempts to FortiGate devices, particularly from unexpected geographic locations or at unusual times
  • Conduct immediate credential rotation for all Fortinet administrative and VPN accounts, especially if devices were exposed during known FortiBleed exploitation windows
  • Deploy network segmentation to limit lateral movement opportunities even if initial VPN access is compromised
  • Enable logging and SIEM integration for Fortinet devices to detect suspicious authentication patterns and post-compromise activity (T1078)