Actor Profile

The FortiBleed campaign is a financially-motivated credential theft operation attributed to actors associated with the INC and Lynx ransomware groups. The campaign focuses on exploiting FortiGate devices to harvest credentials, which are subsequently leveraged for ransomware deployment. Operators managing negotiation panels for both INC and Lynx ransomware families indicate coordination or shared infrastructure between these groups. The primary motivation is financial gain through credential theft enabling ransomware intrusions and extortion.

TTPs (Tactics, Techniques, Procedures)

The FortiBleed campaign employs credential theft techniques targeting FortiGate VPN appliances, likely exploiting known vulnerabilities or misconfigurations to harvest authentication credentials. Stolen credentials provide initial access (T1078 - Valid Accounts) to victim networks, enabling follow-on ransomware deployment. The operation demonstrates coordination between credential theft infrastructure and ransomware negotiation platforms, suggesting integrated access broker and ransomware operator workflows. The use of stolen VPN credentials facilitates lateral movement and persistence within compromised environments prior to ransomware execution.

Targets & Patterns

While specific targeted sectors are not identified in available data, the campaign's focus on FortiGate credentials suggests targeting of organizations utilizing Fortinet VPN infrastructure for remote access. The credential theft model indicates broad opportunistic targeting rather than sector-specific focus, with victim selection likely driven by vulnerable or misconfigured FortiGate deployments. The financial motivation and ransomware deployment pattern suggests targeting of organizations with sufficient resources to pay extortion demands, typical of modern ransomware operations.

Historical Context

The FortiBleed campaign represents an evolution in the access broker ecosystem, where credential theft operations directly feed ransomware deployment pipelines. The linkage between INC and Lynx ransomware groups through shared negotiation panel operators suggests either a rebrand, affiliate relationship, or common operational infrastructure. This pattern aligns with observed trends of ransomware groups operating multiple brands simultaneously or transitioning between identities to evade law enforcement attention and maintain operational continuity.

Defensive Recommendations

  • Audit all FortiGate VPN devices for known vulnerabilities (CVE-2022-40684, CVE-2023-27997) and apply vendor patches immediately
  • Monitor for anomalous VPN authentication patterns including credential reuse from unexpected geolocations or impossible travel scenarios (T1078)
  • Implement multi-factor authentication (MFA) on all VPN and remote access solutions to mitigate credential theft impact
  • Review FortiGate logs for unauthorized configuration changes or credential harvesting indicators, particularly administrative account access
  • Deploy network segmentation to limit lateral movement from VPN entry points and restrict ransomware propagation pathways