SUBJECT PROFILE
SOCRadar's Threat Research Unit on July 2, 2026 confirmed that the FortiBleed credential-harvesting campaign — which targeted over 430,000 FortiGate firewalls globally and collected 110 million+ credentials using a custom Golang sniffer — is directly operated by or feeding into the INC Ransom and Lynx RaaS groups, representing the first confirmed link between mass FortiGate credential theft and ransomware deployment. An operator with access to FortiBleed infrastructure was found simultaneously logged into negotiation panels for both groups, with victim overlap confirmed. The operation involves approximately 20 individuals with defined roles across a ~500-server infrastructure, and actors are also exploiting an unpatched Nextcloud zero-day to expand access.
Financial — mass credential theft via FortiGate network sniffing feeding downstream INC Ransom and Lynx RaaS ransomware deployments
OPERATIONAL HISTORY
FortiGate VPN credential sniffing via custom Golang FortigateSniffer tool (T1040), FortiOS native packet capture abuse (diagnose sniffer packet), credential stuffing (T1110.004), Active Directory domain compromise (T1078), persistent backdoor accounts (username: 'adminin'), Nextcloud zero-day exploitation (T1190), ransomware deployment (INC/Lynx encryptors), double extortion, lateral movement via AD credentials
KNOWN INFRASTRUCTURE
~500 operational servers; custom Golang FortigateSniffer installed on ~19,000 FortiGate devices; INC Ransom and Lynx RaaS negotiation panels; persistent backdoor account 'adminin' on compromised devices; money laundered through ByBit, OKX, BELQI (Russian exchange); Nextcloud zero-day exploitation ongoing