DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // FORTIBLEED-IABFIRST SEEN: FEB 2026

FORTIBLEED IAB

ALSO KNOWN AS: FortiBleed Operator
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Russia (assessed with medium confidence by SOCRadar based on infrastructure and TTPs)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:FEB 2026
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL67/100
RESOURCES67/100
PERSISTENCE70/100
STEALTH62/100
IMPACT76/100

A newly exposed initial access broker operation, active since at least February 2026 and disclosed publicly in June-July 2026, that deployed a custom Golang tool called FortigateSniffer onto compromised FortiGate devices to passively intercept VPN credentials at scale across 150+ countries. SOCRadar confirmed on July 2, 2026 that an operator with access to FortiBleed infrastructure was simultaneously logged into ransomware negotiation panels for both INC Ransom and Lynx, directly tying the credential-harvesting pipeline to live extortion deployments for the first time. The operation involved roughly 20 individuals in a tiered structure and utilized approximately 500 servers globally.

Financial — large-scale initial access brokering feeding credentials harvested from FortiGate firewalls to ransomware affiliates (INC Ransom, Lynx) for downstream extortion

FortiGate exploitation (T1190), passive credential interception via FortiOS 'diagnose sniffer packet' command abuse, credential stuffing, Nextcloud zero-day exploitation (unassigned CVE), persistent backdoor account ('adminin'), Active Directory domain compromise, access brokering to RaaS affiliates

NETWORK INFRASTRUCTURE
FINANCIAL SERVICES
HEALTHCARE
GOVERNMENT
EDUCATION
ENERGY

~500 operational servers identified; FortigateSniffer (custom Golang packet-sniffing tool) installed on ~12,000 FortiGate firewalls; backend C2 infrastructure mapped via Shodan, Censys, and Validin; credentials from 73,000+ FortiGate devices stored on an exposed server; victim data also found on INC Ransom open directories confirming overlap

FILE DATE: FEB 2026
FortiBleed Global Credential Harvest
Large-scale campaign targeting 430,000+ FortiGate firewalls in 150+ countries, harvesting over 110 million credentials via a custom Golang sniffer, with confirmed admin-level access on 409 targets and at least 12 ransomware deployments.
FILE DATE: JUL 2026
INC/Lynx Ransomware Pipeline Link Confirmed
SOCRadar confirmed on July 2 that a single FortiBleed operator was ██████████████████████ panels for both INC Ransom and Lynx RaaS, proving the credential pipeline directly funds downstream ransomware extortion.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn