SUBJECT PROFILE
A newly exposed initial access broker operation, active since at least February 2026 and disclosed publicly in June-July 2026, that deployed a custom Golang tool called FortigateSniffer onto compromised FortiGate devices to passively intercept VPN credentials at scale across 150+ countries. SOCRadar confirmed on July 2, 2026 that an operator with access to FortiBleed infrastructure was simultaneously logged into ransomware negotiation panels for both INC Ransom and Lynx, directly tying the credential-harvesting pipeline to live extortion deployments for the first time. The operation involved roughly 20 individuals in a tiered structure and utilized approximately 500 servers globally.
Financial — large-scale initial access brokering feeding credentials harvested from FortiGate firewalls to ransomware affiliates (INC Ransom, Lynx) for downstream extortion
OPERATIONAL HISTORY
FortiGate exploitation (T1190), passive credential interception via FortiOS 'diagnose sniffer packet' command abuse, credential stuffing, Nextcloud zero-day exploitation (unassigned CVE), persistent backdoor account ('adminin'), Active Directory domain compromise, access brokering to RaaS affiliates
KNOWN INFRASTRUCTURE
~500 operational servers identified; FortigateSniffer (custom Golang packet-sniffing tool) installed on ~12,000 FortiGate firewalls; backend C2 infrastructure mapped via Shodan, Censys, and Validin; credentials from 73,000+ FortiGate devices stored on an exposed server; victim data also found on INC Ransom open directories confirming overlap