Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit FortiGate Firewalls with New Sniffer Tool

Hackers Exploit FortiGate Firewalls with New Sniffer Tool

Posted on June 23, 2026 By CWS

A financially driven cybercriminal group has utilized a specialized Golang-based tool, known as FortigateSniffer, to target over 430,000 FortiGate firewalls worldwide. This campaign has covertly collected more than 110 million credentials since February 2026, including data breaches involving a defense contractor linked to NATO.

Massive Credential Harvesting Campaign Unveiled

Dubbed FortiBleed, this operation has been dissected by SOCRadar’s Threat Research Unit (STRU), revealing one of the largest credential-harvesting efforts focused on network perimeter devices to date. The actors behind this scheme, identified as an Initial Access Broker (IAB) with financial motives, were active through mid-June 2026. They conducted 659 separate harvesting cycles, with some of their infrastructure still operational. Comments in Cyrillic suggest a potential Russian origin, with possible ties to ransomware or state-sponsored entities.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory for organizations to secure their Fortinet devices in light of widespread credential exposure.

FortigateSniffer: The Tool’s Technical Overview

The primary instrument of this attack, FortigateSniffer (also known as fg_sniffer), is a Golang-based tool designed for Linux and Windows systems. Its interface is entirely in Russian, indicating its origins. Unlike traditional malware, this tool exploits FortiOS’s built-in diagnostic command, diagnose sniffer packet, to intercept authentication traffic across 24 protocols, including RADIUS, NTLM, Kerberos, and LDAP.

The intercepted data is transformed into .pcapng format by the SNIFTRAN engine and then analyzed using a PCAP Deep Analysis Toolkit to extract cleartext credentials, NTLMv2 hashes, and session cookies. The tool features evasion techniques such as GeoIP-based filtering and business-hour scheduling to avoid detection.

Phases of the Cyber Attack

The operation followed a structured five-phase lifecycle. Initially, attackers performed reconnaissance using tools like Masscan and Shodan_Recon to identify potential targets, classifying them based on corporate revenue. In the second phase, they gained initial access by generating host-credential combinations for brute-force attacks on FortiGate admin accounts.

The third phase involved deploying the FortigateSniffer tool on compromised devices to harvest credentials. The attackers achieved a 90% success rate in SSH validation across 6,127 devices. The fourth phase focused on cracking harvested hashes and moving laterally within networks using specialized tools.

Finally, the exfiltration phase involved extracting DFS shares from targeted networks without leaving traces. On June 15, 2026, a significant data exfiltration occurred against a NATO-affiliated contractor.

Impact and Global Reach

According to SOCRadar, this campaign exposed 23,406 unique domains across 80,553 FortiGate appliances. Smaller organizations, particularly those with 51 to 200 employees, were predominantly affected, making up 42.3% of the impacted domains. The IT services sector was notably targeted to leverage access into customer environments. Geographically, India and the United States were the most affected, followed by Taiwan, Mexico, and Turkey.

As of mid-June 2026, the campaign remains active, with ongoing updates to the sniffer operations and harvested data directories.

Cyber Security News Tags:CISA, credential harvesting, credential theft, cyber attack, cyber threat, Cybersecurity, Fortigate, FortigateSniffer, Golang tool, Hackers, IT security, NATO, network perimeter, network security, threat actor

Post navigation

Previous Post: Prinz Eugen Ransomware Utilizes RemotePC for Attacks
Next Post: OpenAI Enhances Cybersecurity with GPT-5.5-Cyber

Related Posts

PayPal Breach Exposes Sensitive Customer Information PayPal Breach Exposes Sensitive Customer Information Cyber Security News
OpenVPN Driver Vulnerability Let Attackers to Crash Windows Systems OpenVPN Driver Vulnerability Let Attackers to Crash Windows Systems Cyber Security News
Drone Strikes Disrupt AWS Services in UAE Region Drone Strikes Disrupt AWS Services in UAE Region Cyber Security News
US Confirms Shutdown of BlackSuit Ransomware That Hacked Over 450 Organizations US Confirms Shutdown of BlackSuit Ransomware That Hacked Over 450 Organizations Cyber Security News
AI Browsers Present New Security Risks with Prompt Injection AI Browsers Present New Security Risks with Prompt Injection Cyber Security News
LastPass Data Breach Exposes Customer Information via Klue LastPass Data Breach Exposes Customer Information via Klue Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised
  • Trump Boosts Post-Quantum Cryptography Efforts with New Order

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised
  • Trump Boosts Post-Quantum Cryptography Efforts with New Order

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark