DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // FORTIBLEED-INC-LYNX-CLUSTERFIRST SEEN: FEB 2026

FORTIBLEED OPERATOR (INC/LYNX CLUSTER)

ALSO KNOWN AS: Lynx-INC, INC Ransom, Lynx RaaS
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Russia (assessed; money routing via BELQI Russian exchange; SOCRadar high-confidence attribution)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:FEB 2026
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL65/100
RESOURCES65/100
PERSISTENCE68/100
STEALTH60/100
IMPACT74/100

SOCRadar's Threat Research Unit on July 2, 2026 confirmed that the FortiBleed credential-harvesting campaign — which targeted over 430,000 FortiGate firewalls globally and collected 110 million+ credentials using a custom Golang sniffer — is directly operated by or feeding into the INC Ransom and Lynx RaaS groups, representing the first confirmed link between mass FortiGate credential theft and ransomware deployment. An operator with access to FortiBleed infrastructure was found simultaneously logged into negotiation panels for both groups, with victim overlap confirmed. The operation involves approximately 20 individuals with defined roles across a ~500-server infrastructure, and actors are also exploiting an unpatched Nextcloud zero-day to expand access.

Financial — mass credential theft via FortiGate network sniffing feeding downstream INC Ransom and Lynx RaaS ransomware deployments

FortiGate VPN credential sniffing via custom Golang FortigateSniffer tool (T1040), FortiOS native packet capture abuse (diagnose sniffer packet), credential stuffing (T1110.004), Active Directory domain compromise (T1078), persistent backdoor accounts (username: 'adminin'), Nextcloud zero-day exploitation (T1190), ransomware deployment (INC/Lynx encryptors), double extortion, lateral movement via AD credentials

NETWORK INFRASTRUCTURE
HEALTHCARE
EDUCATION
GOVERNMENT
ENERGY

~500 operational servers; custom Golang FortigateSniffer installed on ~19,000 FortiGate devices; INC Ransom and Lynx RaaS negotiation panels; persistent backdoor account 'adminin' on compromised devices; money laundered through ByBit, OKX, BELQI (Russian exchange); Nextcloud zero-day exploitation ongoing

FILE DATE: JUL 2026
FortiBleed-to-Ransomware Pipeline Confirmed
SOCRadar confirmed July 2, 2026 that the FortiBleed campaign operator was simultaneously managing INC Ransom and Lynx negotiation panels, with at least 12 confirmed ransomware deployments across affected organizations in 150 countries, directly linking 430,000+ targeted FortiGate firewalls to ransomware extortion.
FILE DATE: JUN 2026
FortiBleed Mass Credential Harvest
Campaign targeting 430,000 FortiGate firewalls in 150+ countries using a custom ██████████████████████ exposed server revealed 73,000+ stolen device configs and 110M+ credentials.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn