FBI warns that FortiBleed credential-harvesting attacks are locking out firewall users | #ransomware | #cybercrime


The FBI and U.S. Secret Service warned Tuesday that a monthslong credential harvesting campaign, dubbed FortiBleed, has escalated to the point where Fortinet FortiGate customers are being locked out of their devices. 

Threat actors are using stolen credentials to break into internet-facing FortiGate firewalls and secure socket layer virtual private network gateways across the globe. More than 86,000 devices have been compromised in 194 countries, according to estimates from SOCRadar. 

Authorities warned the main attackers are leveraging compromised FortiGate environments as an initial access point for ransomware. SOCRadar previously linked the FortiBleed campaign to INC and Lynx ransomware operations, and the FBI advisory also links the campaign to Payload ransomware.

“The evidence therefore goes beyond stolen information,” Ensar Seker, CISO at SOCRadar, told Cybersecurity Dive. “Attackers are monetizing working network access.”

Fortinet, in a June advisory, said it believed the hackers were reusing credentials stolen from prior incidents and then employing brute-force techniques against devices with weak password hygiene and without multifactor authentication. 

Keys to the kingdom

An initial access broker is behind the operation, which has targeted more than 430,000 Fortinet FortiGate firewalls worldwide, according to SOCRadar. The operation uses a custom Golang-based tool called a FortiGate sniffer to intercept authentication traffic. 

Exfiltrated password hashes were fed into a GPU accelerated cluster to conduct offline password cracking, according to the FBI advisory. Cracked credentials were then enriched, sorted and validated. High-value targets were prioritized based on revenue and the structure of their networks. 

After gaining access to firewalls, attackers are creating new administrative accounts in order to maintain persistence. Hackers in many cases are deleting or changing passwords on the original FortiGate accounts, which effectively locks the legitimate customer out of their own compromised devices, according to the advisory. 

More than half of the compromised devices are in India, the United States, Taiwan, Mexico and Turkey, according to researchers at CloudSEK. However, the full scope of the campaign reaches into 194 countries. 

The attacks targeted organizations across all of the 16 government-designated critical infrastructure sectors, including energy, communications, food and agriculture, healthcare, government and the defense industry. 

Authorities said if security teams suspect an attack, they should isolate the device, take it offline if necessary and collect relevant artifacts, including log data. 

To prevent future compromises, users should terminate all administrative and VPN sessions and reset credentials. Users are encouraged to enable phishing-resistant multifactor authentication. 



Click Here For The Original Source.

——————————————————–

..........

.

.