# FortiBleed: Attackers Engineer Credential Sniffer to Harvest Credentials from 430,000 Compromised FortiGate Firewalls
Threat actors have escalated an ongoing campaign targeting Fortinet's FortiGate firewalls by deploying a sophisticated Golang-based credential sniffer designed to extract stored credentials and session tokens. The operation has identified approximately 110 million credentials across an estimated 430,000 vulnerable FortiGate instances worldwide, according to security researchers tracking the campaign. The shift from simple exploitation to credential theft represents a critical phase in what has become one of the most damaging firewall compromise campaigns in recent years.
## The Threat: From Access to Extraction
The newly deployed sniffer marks a significant escalation in the FortiBleed campaign. Rather than simply maintaining persistence on compromised firewalls, attackers are now actively harvesting authentication credentials stored within firewall memory and configuration files.
Key characteristics of the attack:
The credential harvesting capability transforms FortiGate firewalls from perimeter security devices into conduits for lateral movement throughout enterprise networks. Once credentials are extracted, attackers gain legitimate-looking access to internal systems, making detection significantly harder.
## Background and Context: The FortiBleed Campaign
The FortiBleed campaign emerged from a confluence of two critical vulnerabilities in FortiGate firewalls:
Together, these vulnerabilities create an unauthenticated-to-code-execution chain that requires no user interaction. Attackers can compromise a firewall with a single HTTP request, gaining full system access without triggering traditional intrusion detection systems.
Timeline of escalation:
| Phase | Activity | Impact |
|-------|----------|--------|
| Phase 1 (Discovery) | Initial exploitation and reconnaissance | Firewall access established |
| Phase 2 (Persistence) | Backdoor installation and access maintenance | Persistent control secured |
| Phase 3 (Current) | Credential harvesting and lateral movement | Internal network compromise begins |
Fortinet released patches in December 2023, but adoption has been glacially slow. Many organizations either missed the patches, delayed deployment due to change management processes, or operate end-of-life FortiGate models no longer receiving security updates.
## Technical Details: How the Sniffer Works
The Golang-based credential sniffer operates through multiple extraction vectors:
1. Memory Dumping
The tool scans FortiGate process memory for plaintext credentials, API tokens, and session cookies. This technique works because FortiGate, like many security appliances, maintains credentials in RAM for frequent use without always encrypting them at rest in memory.
2. Configuration File Parsing
FortiGate stores encrypted credentials in /data/ directories. The sniffer attempts to decrypt configuration backups using hardcoded keys or weak encryption standards, exposing:
3. Session Token Extraction
The tool harvests active session tokens from the firewall's administrative interface. These tokens can be used to masquerade as legitimate administrators without needing original passwords.
4. Log File Analysis
The sniffer parses authentication logs and firewall session logs, which sometimes contain credentials in URL parameters or request bodies (particularly in misconfigured environments).
Discovery Mechanism: The attackers use network scanning to identify FortiGate instances by fingerprinting HTTP headers and SSL certificates. Once identified, the simple authentication bypass allows immediate access. The sniffer is then deployed and begins credential harvesting within minutes.
## Scope and Impact: 430,000 Firewalls, 110 Million Credentials
The scale of this campaign is unprecedented:
Geographic distribution:
Industry sectors:
The 110 million credentials identified include:
Evidence suggests that actual credential extraction has already occurred for at least 50,000 firewalls. Many organizations remain unaware their firewalls have been compromised.
## Implications for Organizations
Immediate risks:
Organizations with unpatched FortiGate firewalls face multiple cascading threats:
1. Internal network compromise — Stolen VPN and administrative credentials enable attackers to access internal systems as trusted users, bypassing network segmentation
2. Data exfiltration — With internal access, attackers can move laterally to access databases, file servers, and intellectual property
3. Supply chain risk — If compromised firewalls belong to managed service providers or technology vendors, their customers are indirectly exposed
4. Credential reuse — Extracted credentials are often reused across multiple services; employees' stolen passwords may unlock cloud accounts, email systems, and development platforms
Long-term consequences:
## Recommendations for Defense
Immediate actions (within 48 hours):
/remote/login endpoints or unusual command executionShort-term hardening (1-2 weeks):
Strategic measures:
---
## HackWire Analysis
The FortiBleed campaign represents a fundamental failure in security fundamentals: patching. These vulnerabilities were disclosed six months ago. The fact that 430,000 firewalls remain unpatched—and are actively being harvested for credentials—reflects a systemic problem in how organizations manage security updates for critical infrastructure.
What makes this campaign particularly dangerous is the *timing*. FortiGate firewalls sit at the network perimeter, supposedly protecting everything behind them. Compromising the firewall doesn't just give attackers access to the network—it gives them *legitimacy*. They can move through the network as administrators or VPN users, triggering none of the alarms that would fire if they arrived from the internet.
The 110 million credentials figure deserves scrutiny. Not all of these will be equally valuable; many will be test accounts, service accounts, or credentials to systems no longer in use. However, even if only 10% are actively usable, that's 11 million valid credentials now in the hands of threat actors. Those credentials become currency in underground markets or tools for follow-on intrusions.
The real story here is what happens next. Organizations are now on a ticking clock: do they patch, rotate credentials, and hope attackers haven't already extracted their sensitive data? Or do they assume they've been breached and launch full incident investigations? Either path is expensive and disruptive. The attackers have already won—they've forced a choice between paying now to patch or paying later to respond to breaches.
For defenders, this is a wake-up call about critical infrastructure security. Firewalls, load balancers, VPN gateways, and other network edge devices should be treated as *systems of record* for security patches. A six-month delay on a perimeter device is unconscionable. Organizations need to establish SLAs for edge device patching: critical vulnerabilities should be deployed within 2 weeks, not 6 months.
— HackWire Editorial
---
## Related Coverage