The ongoing FortiBleed campaign is posing significant threats to organizations by targeting Fortinet devices, notably locking users out. This campaign, which started in June, focuses on Fortinet FortiGate firewalls and SSL VPN appliances accessible via the internet. The attackers are utilizing compromised credentials and brute-force methods to gain control over inadequately secured devices.
Widespread Impact Across Countries
In a matter of days, this attack reached over 86,000 Fortinet devices across 190 nations. SOCRadar has verified that approximately 86,644 devices in 194 countries have been compromised. The attackers are actively seeking out exposed firewalls, using acquired credentials to take control of these devices, significantly affecting global cybersecurity.
The campaign is attributed to a Russian initial access broker, who is leveraging previously stolen credentials to breach devices. Moreover, a joint advisory by the FBI and the US Secret Service warns of the attackers’ tactics, which include changing passwords and deleting user accounts to lock out legitimate users.
Technical Details of the Attack
The attackers have been observed scanning for SSL VPN portals, extracting credentials from infostealer logs, and breaking hashed credentials offline. They expertly map out attack surfaces to avoid detection and use verified credentials to compromise devices. Additionally, they sell VPN configurations and target lists to other cybercriminals, exacerbating the threat.
The advisory highlights the importance of recognizing compromised devices, assessing the extent of intrusions, and evicting attackers to prevent further damage. Strengthening security measures is crucial to thwarting these threats and maintaining network integrity.
Recommendations for Organizations
The FBI and US Secret Service recommend several steps to mitigate these attacks. Organizations should restrict management access, reset all VPN and administrative passwords, and adopt phishing-resistant multifactor authentication. Reviewing firewall and VPN configurations and securing API keys are also advised to reduce vulnerabilities.
Furthermore, companies should analyze logs for any suspicious activity and ensure that credential storage is secure. Such proactive measures are vital for defending against the evolving tactics of cyber attackers.
Related topics include the long-running NPM malware campaign, Anthropic’s cyber verification program for AI access, and Wikimedia’s challenges with rogue OpenAI agents.
