The Federal Bureau of Investigation (FBI) and U.S. Secret Service have released a critical cybersecurity alert regarding the ongoing FortiBleed campaign. This operation targets Fortinet FortiGate firewalls and SSL VPN gateways, posing a significant threat to organizations worldwide. The advisory highlights that over 86,644 devices in 194 countries have been affected, placing numerous entities at risk.
Global Impact of the FortiBleed Campaign
Unlike a singular vulnerability, FortiBleed exploits weak, reused, or leaked credentials to infiltrate FortiGate devices. Attackers leverage outdated SHA-256 password storage to facilitate password cracking across distributed infrastructures. The campaign became evident when its operators inadvertently exposed a server containing critical tools and data.
The disclosed infrastructure reveals a sophisticated operation, scanning for vulnerable FortiGate SSL VPN portals and testing compromised passwords. This organized effort involves credential stuffing and password spraying, enabling attackers to gain and maintain access by creating new administrator accounts, potentially locking out legitimate users.
Threat Tactics and Techniques
According to the FBI, FortiBleed employs several MITRE ATT&CK techniques, including active scanning, password spraying, and credential stuffing. These methods allow attackers to access and exfiltrate data, while also removing legitimate access to affected systems. The campaign is linked to initial-access brokers aiding ransomware efforts, posing a broader threat to organizational security.
Organizations are urged to scrutinize Fortinet administrative and VPN accounts, particularly unfamiliar ones like forticloud-sync and fgtsecure. Security teams should investigate unusual API keys, suspicious authentication activities, and connections to known malicious infrastructure as detailed in the advisory.
Preventive Measures and Recommendations
To mitigate the threat, agencies recommend restricting external management access and removing internet-based administration wherever feasible. Administrators should terminate active sessions, reset credentials, and enforce multifactor authentication for remote access. Additionally, organizations should ensure that administrator credentials utilize PBKDF2 rather than legacy hashing methods.
Regular log reviews for unauthorized accounts, suspicious logins, and configuration changes are essential. Monitoring for indicators of compromise such as specific IP addresses and unusual network behavior is crucial to thwart potential breaches and secure networks proactively.
In conclusion, the FortiBleed campaign represents a severe cybersecurity risk with widespread implications. Organizations must act swiftly to secure their networks and prevent potential downstream ransomware attacks. Staying informed and adopting robust security practices can help mitigate these threats effectively.
