
FORTIBLEED, a credential‑harvesting campaign that has intercepted authentication traffic from FortiGate firewalls, is now being used by the ransomware groups Inc and Lynx to launch attacks. Security researchers at SOCRadar traced the stolen credentials to dozens of ransomware deployments affecting hundreds of endpoints across multiple sectors.
The attackers employed a tool called FortigateSniffer to capture login credentials without delivering any malicious payload, allowing them to remain undetected while harvesting usernames and passwords. Once obtained, the credentials provided administrative access on 409 distinct firewalls and enabled full domain compromise on 354 of those targets. The operation also leveraged a previously unknown flaw in Nextcloud to deepen footholds inside victim networks.
According to the research, the campaign has probed roughly 430 000 FortiGate devices worldwide and successfully harvested credentials from about 12 000 of them. In total, more than 110 million username‑password pairs have been collected since February, giving the threat actors a vast pool for lateral movement. The scale of the collection means that even a small subset of valid credentials can yield privileged access to critical systems.
Inc and Lynx have begun using the stolen FortiGate credentials to deploy ransomware, with at least twelve confirmed incidents resulting in encryption of hundreds of workstations and servers. The overlap in infrastructure indicates a single operator or tightly linked crew is managing both the credential theft and the ransomware payloads. This convergence raises the risk that further compromises will quickly evolve into full‑scale extortion events.
Administrators should immediately apply the latest FortiOS patches and review any authentication logs for unusual patterns, especially repeated failed logins from unexpected locations. Enforcing multi‑factor authentication on all management interfaces reduces the value of harvested passwords. Network segmentation can limit the ability of an attacker who gains a foothold on a firewall to reach internal servers and domain controllers. Additionally, organisations ought to monitor Nextcloud instances for signs of exploitation and apply any available mitigations for the zero‑day flaw.
Security teams are encouraged to hunt for the FortigateSniffer artifact or related network indicators and to share any findings with trusted information‑sharing communities. Continuous threat‑intelligence feeds that tag Inc and Lynx activity can help prioritize alerts and speed up response times. Staying vigilant against credential‑theft campaigns remains a core defence against the ransomware threat they enable.