DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // FORTIBLEED-RUSSIAN-IABFIRST SEEN: FEB 2026

FortiBleed IAB (SantaAd / Unattributed Russian IAB)

ALSO KNOWN AS: SantaAd (forum alias), FortiBleed threat actor
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Russia (Russian-speaking, assessed by Recorded Future Insikt Group, SOCRadar, and researcher Volodymyr Diachenko)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:FEB 2026
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL79/100
RESOURCES79/100
PERSISTENCE82/100
STEALTH74/100
IMPACT88/100

Active since at least February 2026, FortiBleed is the largest confirmed Fortinet credential-harvesting campaign in history, compromising verified admin and SSL VPN credentials for 86,644 FortiGate devices across 194 countries — roughly 50% of all internet-facing Fortinet firewalls globally. The Russian-speaking IAB deployed a custom Golang-based tool (FortigateSniffer) to passively capture cleartext credentials passing through compromised firewalls, cracked hashes via a 45-GPU Hashtopolis cluster, and pivoted into Active Directory environments. A NATO defense contractor was confirmed compromised with classified documents exfiltrated on June 15. CISA, UK NCSC, and Fortinet all issued emergency advisories by June 18–19, 2026.

Financially motivated initial access brokerage — large-scale automated credential harvesting of FortiGate firewalls for resale to ransomware gangs and potentially Russian state-sponsored APTs

Mass scanning via Masscan/Shodan (T1595), SSH brute-force against FortiGate (T1110), passive network sniffing via FortiOS diagnostic abuse (T1040), Kerberos hash cracking (T1558), credential stuffing from prior breach datasets (T1110.004), Active Directory lateral movement (T1021), DFS backup exfiltration (T1039), credential marketplace sales

GOVERNMENT
DEFENSE
CRITICAL INFRASTRUCTURE
TELECOMMUNICATIONS
FINANCIAL SERVICES
HEALTHCARE
MANUFACTURING
SMBS

FortigateSniffer (custom Golang sniffer), CyberStrikeAI autonomous scanning framework, 45-GPU Hashtopolis cracking cluster, automated validation scripts, structured dark web sales infrastructure (Exploit Forum alias SantaAd listing access at $30,000–$60,000); campaign also targeting Sophos SSL-VPN, Synology NAS, Citrix, RDWeb, MSSQL

FILE DATE: FEB 2026
FortiBleed Campaign Initiation
Automated multi-vendor credential harvesting operation begins, targeting FortiGate firewalls, Sophos, Citrix, and MSSQL servers globally using brute-force and passive sniffing.
FILE DATE: JUN 2026
FortiBleed Public Disclosure & NATO Contractor Compromise
Researcher Diachenko exposes attacker server June 13; by June 15, NATO ██████████████████████ backup data exfiltrated; CISA/NCSC emergency advisories issued June 18-19; 86,644 verified compromised devices confirmed, 110M credentials captured.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn