FortiBleed Vulnerability: Attackers Exploit Fortinet Firewalls to Lock Out Admins
FortiBleed remains active, with threat actors exploiting vulnerabilities in Fortinet firewalls to prevent administrators from accessing critical systems.
FortiBleed Threat Overview
FortiBleed remains active, with threat actors exploiting vulnerabilities in Fortinet firewalls to prevent administrators from accessing critical systems. A joint advisory from the FBI and U.S. Secret Service highlights that some organizations have been locked out of their Fortinet FortiGate firewalls and SSL VPN gateways due to the ongoing FortiBleed campaign.
Joint Advisory from FBI and U.S. Secret Service
The advisory, which references findings from SOCRadar, confirms that over 86,644 devices across 194 countries have been compromised. Attackers target internet-facing Fortinet infrastructure, leveraging initial access to manipulate user accounts.
In certain cases, threat actors delete or alter existing administrative credentials, effectively blocking organizations from regaining control of affected systems.
Attack Methods and Persistent Access
The malicious actors also establish persistent access by creating new user accounts not previously present on the devices. This dual approach ensures continued control while enabling lateral movement within compromised networks.
Recovery Challenges
Recovery efforts for impacted entities extend beyond standard patching and password resets. The advisory warns that attackers are actively scanning exposed Fortinet firewalls using credentials obtained from prior breaches.
Credential Stuffing and Password Spraying
These credentials are derived from leaked data and infostealer logs, which are then used in credential stuffing and password spraying campaigns. Attackers extract password hashes from compromised systems and crack them using GPU clusters equipped with tools like Hashcat and Hashtopolis.
Reconnaissance and Ransomware Linkages
Once credentials are validated, attackers perform reconnaissance to identify privileged accounts within Active Directory. This phase includes mapping organizational structures and prioritizing targets based on financial value and network complexity. The compromised access is subsequently sold to affiliates linked to the INC/Lynx and Payload ransomware groups.
Mitigation Strategies and Warnings
The FBI and Secret Service have identified specific IP addresses and usernames associated with the attacks, alongside recommended mitigation strategies. While reporting incidents is voluntary, the agencies urge affected organizations to disclose breaches and advise against paying ransom demands.
Evolving Threat Landscape
The advisory underscores the evolving tactics of threat actors, emphasizing the need for continuous monitoring and proactive security measures to counteract persistent threats targeting critical infrastructure.
