An ecrime group has somehow gained access to 75k Fortinet firewall devices - dubbed Fortibleed

Blog https://www.infostealers.com/article/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure/

Check if your domain is impacted: https://www.hudsonrock.com/fortinet

I’ve verified the data is real. They’ve been dumping the Fortinet config - not sure how yet - and then cracking the passwords it appears. Data is being resold online. #fortibleed

Data looks like this, appears they validated creds too.

It’s similar to the Belsen Group thing, although that was a smaller collection of devices - prior thread

https://cyberplace.social/@GossiTheDog/113834848200229959

Kevin Beaumont (@[email protected])

Attached: 2 images A new group, Belsen Group, claim to have released Fortigate configs for 15k firewalls. #threatintel

Cyberplace

So there are definitely devices which weren't in the Belsen Group post back last year, in fact almost all of them weren't.

On how they got the passwords - until about a year ago, FortiOS (Fortinet firewall OS) stored admin passwords SHA-256 salted, which can be bruteforced.

In an update about a year ago, if installed and admins log in, passwords are stored much more securely - but most orgs won't be that condition yet. In other words, if you dump the config you could get the passwords.

FortiBleed — 75k Fortinet firewalls have admin passwords cracked

A look inside a massive dump of allowing access to organisations protected by Fortigate firewall solutions.

Medium

Lol, the #FortiBleed data was found in an opendir on a webserver 🤣 truly GenAI is going to take over 😜

"They accidentally left an open directory with artefacts, connection strings, tooling, scripts and data online. Analytics obtained via their cron jobs, bash histories, logs etc,"

https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/

FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.

A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.

BleepingComputer
#GAYINT list of impacted #FortiBleed domains (this is basically email addresses of admin accounts on the device btw) https://blog.gayint.org/intel/fortibleed.txt
#GAYINT list of impacted #FortiBleed IPs. Not all as I couldn't write the parser properly. http://owned.lab6.com/~gossi/research/public/fortibleed/some-fortibleed-ips.txt

Fortinet appear to be telling press the #Fortibleed breach is made up of prior breaches and brute forcing.. but I’ve seen the breach data and it includes many passwords not in prior dumps, and I’ve worked with impacted orgs and they report no brute forcing of impacted accounts.

I think there may be some confusion about this one - the brute forcing is the cracking of the passwords by the threat actor, which is done locally.

Watch this space on this one anyhoo.

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways

Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.

National Cyber Security Centre

To be transparent about this, a threat actor has been claiming they have an exploit to get FortiOS device password hashes remotely from config for the past month. It’s currently unclear how. They claim it’s an exploit of an unpatched vuln. Their claims predate the discovery of this dump.

If I end up having to set up another FortiGate firewall honeypot to figure out what’s going on.. I’ll British tut and get on with it.

Some kind #FortiBleed victims got me to look at their situations. Some IOCs performing remote config dumps:

193.8.186.7
80.75.212.113
213.21.239.65

Look for inbound TCP traffic to Fortigate devices. If seen log into the devices and look for config dump events from those IPs.

Config dumps (including crackable password hashes) have been going on for around a month.

If you have IPsec site to site VPN tunnels on the impacted Fortinets you need to rebuild the tunnels with new keys both ends.

AL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devices - Canadian Centre for Cyber Security

AL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devices

Canadian Centre for Cyber Security
CloudSEK look at the open directory that had all the #FortiBleed tooling and data in it. It's a good report, although I disagree with their conclusion - it's still an absolutely truck load of creds, even if that particular opendir only had internal network details for a few thousand orgs. https://www.cloudsek.com/blog/inside-the-fortibleed-open-directory-a-technical-analysis-of-what-the-attacker-left-behind
Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind | CloudSEK

An exposed attacker server has revealed FortiBleed’s complete operation—from credential harvesting and GPU-powered cracking to network intrusion and access sales. CloudSEK’s analysis separates verified compromises from inflated claims, uncovering what the attackers actually achieved.

Update on FortiBleed by me

New IOCs doing config dumps (including an IP addressed owned by Fortigate), details on movement inside networks etc.

https://doublepulsar.com/an-update-on-fortibleed-whats-happening-with-victim-orgs-c0671a50e7f4

An update on FortiBleed — what’s happening with victim orgs

Attackers on internal networks, password cracked and other Friday fun.

Medium

Fortinet have put out a blog about FortiBleed finally - where they don’t mention configuration exports (which is definitely happening at scale, I have receipts) or password hash cracking (we have the bash history of the user doing it).. but instead link Fortibleed to a prior marketing blog called “Attacks at the speed of AI” 🤦‍♀️

https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices?lctg=197390370

Analysis of Reported Credential Compromise of FortiGate Devices | Fortinet Blog

What you need to know about “FortiBleed”…

Fortinet Blog

There's some more analysis of the #FortiBleed attack infrastructure here:
https://zenox.ai/en/fortibleed-anatomy-of-the-fortibleed-campaign-based-on-the-server-that-the-attackers-themselves-left-exposed/

It's not mentioned but they cracked around 170k AD account passwords. Also all the comments on the custom source is written in Russian.

Also, there is a GenAI angle I missed - they used an open source pentesting AI agent framework to try to automate attacks. It doesn't look like that bit worked very well.

@GossiTheDog Why is there so much confusion between machine learning and automation?
@Sempf @GossiTheDog Recency bias?