# FortiBleed: Attackers Engineer Credential Sniffer to Harvest Credentials from 430,000 Compromised FortiGate Firewalls


Threat actors have escalated an ongoing campaign targeting Fortinet's FortiGate firewalls by deploying a sophisticated Golang-based credential sniffer designed to extract stored credentials and session tokens. The operation has identified approximately 110 million credentials across an estimated 430,000 vulnerable FortiGate instances worldwide, according to security researchers tracking the campaign. The shift from simple exploitation to credential theft represents a critical phase in what has become one of the most damaging firewall compromise campaigns in recent years.


## The Threat: From Access to Extraction


The newly deployed sniffer marks a significant escalation in the FortiBleed campaign. Rather than simply maintaining persistence on compromised firewalls, attackers are now actively harvesting authentication credentials stored within firewall memory and configuration files.


Key characteristics of the attack:


  • Golang implementation — The sniffer is written in Go, making it portable across multiple architectures and operating systems
  • In-memory extraction — Targets credentials cached in firewall RAM during active sessions
  • Configuration file harvesting — Extracts plaintext or weakly encrypted credentials from FortiGate backup files
  • VPN credentials — Prioritizes harvesting of remote access credentials used by enterprise employees
  • API tokens and SSH keys — Captures administrative credentials used for remote management

  • The credential harvesting capability transforms FortiGate firewalls from perimeter security devices into conduits for lateral movement throughout enterprise networks. Once credentials are extracted, attackers gain legitimate-looking access to internal systems, making detection significantly harder.


    ## Background and Context: The FortiBleed Campaign


    The FortiBleed campaign emerged from a confluence of two critical vulnerabilities in FortiGate firewalls:


  • CVE-2024-21762 — An authentication bypass vulnerability in FortiGate OS versions before 7.0.4
  • CVE-2024-23113 — A subsequent vulnerability allowing post-authentication arbitrary command execution

  • Together, these vulnerabilities create an unauthenticated-to-code-execution chain that requires no user interaction. Attackers can compromise a firewall with a single HTTP request, gaining full system access without triggering traditional intrusion detection systems.


    Timeline of escalation:


    | Phase | Activity | Impact |

    |-------|----------|--------|

    | Phase 1 (Discovery) | Initial exploitation and reconnaissance | Firewall access established |

    | Phase 2 (Persistence) | Backdoor installation and access maintenance | Persistent control secured |

    | Phase 3 (Current) | Credential harvesting and lateral movement | Internal network compromise begins |


    Fortinet released patches in December 2023, but adoption has been glacially slow. Many organizations either missed the patches, delayed deployment due to change management processes, or operate end-of-life FortiGate models no longer receiving security updates.


    ## Technical Details: How the Sniffer Works


    The Golang-based credential sniffer operates through multiple extraction vectors:


    1. Memory Dumping

    The tool scans FortiGate process memory for plaintext credentials, API tokens, and session cookies. This technique works because FortiGate, like many security appliances, maintains credentials in RAM for frequent use without always encrypting them at rest in memory.


    2. Configuration File Parsing

    FortiGate stores encrypted credentials in /data/ directories. The sniffer attempts to decrypt configuration backups using hardcoded keys or weak encryption standards, exposing:

  • VPN user credentials
  • Administrative account passwords
  • RADIUS and LDAP integration credentials
  • Cloud API credentials for backup and logging services

  • 3. Session Token Extraction

    The tool harvests active session tokens from the firewall's administrative interface. These tokens can be used to masquerade as legitimate administrators without needing original passwords.


    4. Log File Analysis

    The sniffer parses authentication logs and firewall session logs, which sometimes contain credentials in URL parameters or request bodies (particularly in misconfigured environments).


    Discovery Mechanism: The attackers use network scanning to identify FortiGate instances by fingerprinting HTTP headers and SSL certificates. Once identified, the simple authentication bypass allows immediate access. The sniffer is then deployed and begins credential harvesting within minutes.


    ## Scope and Impact: 430,000 Firewalls, 110 Million Credentials


    The scale of this campaign is unprecedented:


    Geographic distribution:

  • North America: 45% of identified instances
  • Europe: 28%
  • Asia-Pacific: 18%
  • Other regions: 9%

  • Industry sectors:

  • Financial services (23%)
  • Healthcare (18%)
  • Government and defense (15%)
  • Retail and e-commerce (12%)
  • Manufacturing (10%)
  • Technology (9%)
  • Other sectors (13%)

  • The 110 million credentials identified include:

  • 45 million VPN account credentials
  • 32 million cloud service API keys and tokens
  • 18 million local administrative credentials
  • 12 million third-party application passwords
  • 3 million SSH keys and certificate credentials

  • Evidence suggests that actual credential extraction has already occurred for at least 50,000 firewalls. Many organizations remain unaware their firewalls have been compromised.


    ## Implications for Organizations


    Immediate risks:


    Organizations with unpatched FortiGate firewalls face multiple cascading threats:


    1. Internal network compromise — Stolen VPN and administrative credentials enable attackers to access internal systems as trusted users, bypassing network segmentation

    2. Data exfiltration — With internal access, attackers can move laterally to access databases, file servers, and intellectual property

    3. Supply chain risk — If compromised firewalls belong to managed service providers or technology vendors, their customers are indirectly exposed

    4. Credential reuse — Extracted credentials are often reused across multiple services; employees' stolen passwords may unlock cloud accounts, email systems, and development platforms


    Long-term consequences:


  • Incident response at scale — Organizations may require full credential rotation, forcing password resets across all dependent systems
  • Regulatory exposure — Healthcare and financial services organizations face potential breach notifications to regulators and customers
  • Insurance impact — Breach remediation costs and potential liability exclusions if organizations failed to patch known critical vulnerabilities

  • ## Recommendations for Defense


    Immediate actions (within 48 hours):


  • Inventory FortiGate firewalls — Identify all FortiGate instances in your environment and document their OS versions
  • Verify patch status — Confirm all FortiGate devices run patched versions (7.0.4 or later for vulnerable versions)
  • Rotate credentials — Change all credentials used on or accessible through FortiGate firewalls, particularly VPN accounts and administrative credentials
  • Enable logging review — Check firewall logs for suspicious HTTP requests to /remote/login endpoints or unusual command execution

  • Short-term hardening (1-2 weeks):


  • Implement network segmentation — Restrict FortiGate's ability to access internal networks, even if compromised
  • Enable multi-factor authentication — Require MFA for all remote access and administrative interfaces
  • Deploy anomaly detection — Monitor for unusual credential usage patterns or lateral movement after authentication
  • Credential monitoring — Subscribe to dark web monitoring services to detect if your organization's stolen credentials appear for sale

  • Strategic measures:


  • Review FortiGate usage — Evaluate whether FortiGate firewalls are necessary given the attack surface they represent; consider replacement with alternatives that have better security track records
  • Strengthen supply chain visibility — If your organization uses managed service providers, verify their FortiGate patch status
  • Incident response readiness — Assume that firewalls may already be compromised; develop response procedures for large-scale credential compromise

  • ---


    ## HackWire Analysis


    The FortiBleed campaign represents a fundamental failure in security fundamentals: patching. These vulnerabilities were disclosed six months ago. The fact that 430,000 firewalls remain unpatched—and are actively being harvested for credentials—reflects a systemic problem in how organizations manage security updates for critical infrastructure.


    What makes this campaign particularly dangerous is the *timing*. FortiGate firewalls sit at the network perimeter, supposedly protecting everything behind them. Compromising the firewall doesn't just give attackers access to the network—it gives them *legitimacy*. They can move through the network as administrators or VPN users, triggering none of the alarms that would fire if they arrived from the internet.


    The 110 million credentials figure deserves scrutiny. Not all of these will be equally valuable; many will be test accounts, service accounts, or credentials to systems no longer in use. However, even if only 10% are actively usable, that's 11 million valid credentials now in the hands of threat actors. Those credentials become currency in underground markets or tools for follow-on intrusions.


    The real story here is what happens next. Organizations are now on a ticking clock: do they patch, rotate credentials, and hope attackers haven't already extracted their sensitive data? Or do they assume they've been breached and launch full incident investigations? Either path is expensive and disruptive. The attackers have already won—they've forced a choice between paying now to patch or paying later to respond to breaches.


    For defenders, this is a wake-up call about critical infrastructure security. Firewalls, load balancers, VPN gateways, and other network edge devices should be treated as *systems of record* for security patches. A six-month delay on a perimeter device is unconscionable. Organizations need to establish SLAs for edge device patching: critical vulnerabilities should be deployed within 2 weeks, not 6 months.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)