FortiBleed Credential Theft Campaign Tied to Lynx Ransomware Operations

The massive FortiBleed credential theft operation just got a lot more interesting. Researchers at SOCRadar have linked it directly to the INC and Lynx ransomware groups, suggesting those stolen Fortinet credentials weren’t just sitting around doing nothing.

Earlier this month, a server containing credentials from over 73,000 Fortinet devices was found exposed online. It had FortiGate config files, harvested credentials, and infrastructure for cracking password hashes and running credential-stuffing attacks.

Now SOCRadar says the operation is much bigger than first reported. They found it targeted more than 430,000 FortiGate firewalls worldwide, with traffic sniffers deployed on roughly 19,000 devices. About 500 servers were used in the operation. After notifications went out, the number of compromised devices dropped to around 11,000.

The link to ransomware came from a Windows server in the FortiBleed infrastructure. Investigators found browser sessions accessing the administrative panels for both Lynx and INC ransomware groups, showing negotiation dashboards and victim chats. That’s direct evidence that whoever was running FortiBleed was also involved in ransomware negotiations.

The attackers used a custom tool called “FortiGate Sniffer” to intercept VPN credentials from network traffic. They also set up persistent backdoor accounts using the username “adminin” on compromised systems. SOCRadar believes the group exploited an undisclosed Nextcloud zero-day to expand access after initial compromises.

INC Ransom has been operating as a ransomware-as-a-service platform since mid-2023. Lynx emerged in mid-2024 and is widely believed to be a rebrand of INC. The FortiBleed operation appears to have around 20 members with defined roles.

SOCRadar plans to release a second technical paper with indicators of compromise once its investigation wraps up.