Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory

874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5

TLP:CLEAR
Active

SHA-256 Hash

Description

FortiBleed is a large-scale credential compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways globally. The operation employs a sophisticated credential pipeline utilizing credential stuffing, password spraying, configuration harvesting, offline cracking, and post-authentication capture processing. Reverse engineering of the CyberStrike Harvester v1.5 binary revealed a comprehensive workflow converting FortiGate access into multi-protocol credential extraction, hash cracking via Hashcat/Hashtopolis GPU clusters, VPN-bound Active Directory and SMB access, and file-share exfiltration. The campaign affected devices across 194 countries and uses a seven-VM Kali lab infrastructure with automated tooling including FortiGate Sniffer panels, Telegram-orchestrated cracking bots, and Python/Impacket-based lateral movement tools. One documented exfiltration operation collected 121.43 GB from internal file shares. The operation appears to function as initia...

Sightings (0)

No sightings recorded yet

Details

Name / Label
Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory
Pattern Type
STIX
Confidence
75%
Valid From
Jul 24, 2026 04:00
Total Sightings
0
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.