# FortiBleed Campaign Weaponizes Custom Sniffers to Harvest Credentials from FortiGate Firewalls


A large-scale cyberattack campaign targeting Fortinet FortiGate devices has leveraged custom packet-sniffing tools to steal administrative credentials and authentication secrets directly from compromised network firewalls, according to security researchers at SOCRadar. The campaign, tracked as FortiBleed, represents a significant escalation in attacks against critical network infrastructure, exploiting vulnerabilities in widely deployed enterprise firewalls to gain persistent access to organizations' networks.


## The Threat


The FortiBleed campaign represents a sophisticated multi-stage attack chain designed to compromise FortiGate firewall appliances and extract sensitive authentication data. Once attackers gain initial access to a vulnerable FortiGate device, they deploy custom packet-sniffing tools that operate at the network stack level to intercept and harvest authentication credentials traversing the firewall.


Key attack indicators include:

  • Custom sniffer tools installed on compromised FortiGate instances
  • Real-time interception of authentication traffic and credentials
  • Harvesting of administrative access tokens and session credentials
  • Lateral movement enabled through stolen credentials

  • The campaign has been observed targeting organizations across multiple sectors, with SOCRadar detecting thousands of compromised FortiGate instances showing signs of active credential harvesting operations. The ability to extract credentials from within the firewall itself gives attackers unprecedented visibility into authentication flows passing through the network perimeter.


    ## Background and Context


    FortiGate firewalls are among the most widely deployed network security appliances globally, protecting millions of networks ranging from small businesses to Fortune 500 enterprises and critical infrastructure operators. These devices sit at the network edge and are responsible for enforcing security policies, blocking malicious traffic, and protecting internal networks from external threats.


    The significance of compromising FortiGate devices cannot be overstated:


    | Impact Area | Risk Level | Details |

    |-------------|-----------|---------|

    | Network visibility | Critical | Attackers gain access to all traffic flows through the firewall |

    | Authentication interception | Critical | Credentials for internal systems can be harvested in transit |

    | Persistent access | Critical | Compromised firewall enables long-term network presence |

    | Lateral movement | High | Stolen credentials enable breach of internal systems |

    | Data exfiltration | High | Attackers can monitor and intercept sensitive data |


    Fortinet has a history of vulnerabilities affecting FortiGate devices, including the critical CVE-2022-41328 and CVE-2023-27997 vulnerabilities that have been exploited in the wild. However, the FortiBleed campaign appears to exploit either previously unknown vulnerabilities or misconfigurations in FortiGate instances, taking advantage of inadequate patch management and insufficient network segmentation.


    ## Technical Details


    The FortiBleed attack chain operates through several distinct stages:


    Initial Compromise: Attackers typically gain initial access through exploitation of known vulnerabilities, exposed management interfaces, or weak administrative credentials. FortiGate devices exposed to the internet without proper access controls are particularly susceptible.


    Persistence and Tooling: Once inside the FortiGate system, attackers deploy custom packet-sniffing utilities designed to operate within the FortiGate OS environment. These are not standard network tools, but rather purpose-built sniffer implementations that:

  • Hook into the firewall's kernel network stack
  • Capture authentication traffic without triggering traditional detection mechanisms
  • Filter for credentials and authentication tokens
  • Exfiltrate harvested data to attacker-controlled servers

  • Credential Harvesting: The custom sniffers intercept multiple types of credentials, including:

  • Administrative usernames and passwords
  • API tokens and session identifiers
  • VPN authentication credentials
  • SSH keys and certificate materials
  • Cloud service tokens and federation credentials

  • Data Exfiltration: Harvested credentials are systematically exfiltrated, potentially enabling attackers to compromise downstream infrastructure including internal management systems, cloud environments, and critical applications.


    ## Implications


    The widespread nature of the FortiBleed campaign creates significant risks for affected organizations:


    Immediate Exposure: Organizations with compromised FortiGate devices have their network perimeters under direct attacker control, meaning all traffic entering or leaving the network is potentially visible to threat actors.


    Credential Compromise: The harvesting of authentication credentials enables attackers to move laterally within networks, bypass traditional access controls, and establish persistent footholds in internal infrastructure.


    Supply Chain Risk: Managed Service Providers (MSPs) and service providers operating FortiGate devices on behalf of customers could enable single-point compromise affecting multiple client networks simultaneously.


    Regulatory and Compliance Impact: Organizations in regulated industries (financial services, healthcare, critical infrastructure) may face significant compliance consequences, as this type of compromise typically triggers breach notification requirements and regulatory investigations.


    Advanced Persistent Threat Activity: The sophistication of the custom tooling and the scale of the campaign suggests involvement by advanced threat actors, potentially state-sponsored groups or well-funded cybercriminal organizations.


    ## Recommendations


    Organizations operating FortiGate firewalls should take immediate action:


    Immediate Actions (0-48 hours):

  • Verify all FortiGate devices are running the latest patched firmware versions
  • Review firewall logs for signs of unauthorized access or suspicious processes
  • Audit administrative user accounts for unauthorized access
  • Reset credentials for all administrative accounts
  • Implement additional MFA controls on management interfaces

  • Short-term Actions (1-2 weeks):

  • Conduct forensic analysis of potentially compromised FortiGate devices
  • Review VPN logs and authentication records for anomalous access patterns
  • Reset credentials for any accounts accessed through compromised firewalls
  • Assume credential compromise and rotate secrets for downstream systems
  • Implement network segmentation to limit lateral movement if breach is confirmed

  • Long-term Mitigation:

  • Deploy enhanced monitoring and detection tools specifically targeting FortiGate security appliances
  • Implement zero-trust network architecture to reduce reliance on perimeter security
  • Establish privileged access management (PAM) controls for firewall administration
  • Maintain rigorous patch management and vulnerability assessment programs
  • Consider redundant or backup firewall implementations

  • ---


    ## HackWire Analysis


    The FortiBleed campaign illuminates a critical vulnerability in how organizations approach network perimeter security. Firewalls have long been treated as a trust boundary—a device you protect rather than a device that could become a pivot point. But when a firewall is compromised, the assumption of that boundary collapses completely.


    What makes this campaign particularly concerning is not just the credential theft, but the *location* of the theft. Traditional attackers must establish footholds inside the network, set up command infrastructure, and exfiltrate data across monitored channels. FortiBleed attackers achieve visibility into network traffic *before it even enters* the protected zone. They harvest credentials *at the moment of authentication*, potentially weeks before defenders realize anything is wrong.


    The custom sniffer development also signals sophistication. While packet sniffing is not a novel technique, building purpose-built tools that operate stealthily within FortiGate OS, circumvent logging, and execute reliably across firmware versions requires deep platform knowledge. This is not script-kiddie activity—it's organized, well-resourced threat group behavior.


    Organizations need to confront an uncomfortable truth: perimeter security is no longer a reliable trust boundary. The shift to zero-trust architecture isn't just a best practice recommendation anymore—for many organizations, it's rapidly becoming a necessity. If your firewall can become an attacker's observation post, then the firewall cannot be the foundation of your security model.


    Additionally, the widespread nature of this campaign should prompt urgent conversations about supply chain risk. Managed service providers, outsourced security operations centers, and cloud infrastructure providers handling FortiGate management should immediately audit their customer estates for signs of compromise. One compromised MSP environment could affect hundreds of downstream organizations.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)