Details from an FBI investigation into the ongoing FortiBleed attacks reveal that victims could be locked out of their own firewall even as attackers remain logged in.
After gaining access to a backend server left exposed by the attackers, the FBI and US Secret Service have shared new details of an operation that has already affected more than 80,000 devices worldwide.
The server gave investigators a look at the infrastructure behind the operation, including systems used to process stolen credentials, crack password hashes, and identify potential targets. The operators were also found ranking organizations based on their revenue and network structure, the FBI said in an advisory.
“FortiBleed isn’t a vulnerability story anymore,” said Muhammad Yahya Patel, vCISO, cybersecurity advisor EMEA at Huntress. “It’s a persistence story. The credentials were taken months ago. The question every organization needs to answer is whether they’re still being used right now.”
Attackers have created administrative accounts, enumerated Active Directory environments, and used compromised credentials for lateral movement, the FBI added. Access obtained through the campaign has also been offered to ransomware affiliates, including INC/Lynx and Payload ransomware.
Attackers can lock defenders out
The newly disclosed lockout capability is a more immediate operational risk for affected organizations. The FBI said some victims may lose access to their FortiGate devices when attackers delete or change the passwords of existing accounts.
During an intrusion, attackers create new accounts that were not previously present on the device. In some cases, they then delete existing accounts, preventing organizational persistence and attempting to move laterally through the environment.
“When you no longer have access to your own firewall, you cannot just apply a software patch and move on,” said Ben Bernstein, manager, cybersecurity advisors team at Huntress. “These attackers know organizations will have to physically factory reset and rebuild the hardware before the encryption starts.”
FBI’s newly published account names and infrastructure indicators can help organizations investigate potential compromise. The agency recommended reviewing Fortinet accounts and configurations for unauthorized changes, checking firewall, VPN, authentication, and domain controller logs for suspicious activity, and looking for unknown or unexpected REST API keys that could provide attackers with automated access to FortiGate systems.
Terminating active administrative and VPN sessions, resetting Fortinet administrative and VPN credentials, enforcing phishing-resistant MFA, and using PBKDF2 for admin credentials were also recommended.
Hackers rented GPUs to crack passwords
Among the newly disclosed details are the use of rented GPU infrastructure for password cracking, Hashcat and Hashtopolic to distribute cracking jobs, and tooling to validate and prioritize recovered credentials.
“Attackers are stealing configuration files, cracking password hashes offline on their own hardware, and logging in on the first try without generating a single failed login alert,” Bernstein pointed out. “Targeting edge devices like VPNs and firewalls is nothing new, but this FortiBleed campaign stands out because of the contrast between the silent initial access and the aggressive takeover that follows.”
The infrastructure uncovered by investigators included command-and-control (C2) servers, relay nodes, and scanning systems, with several IP addresses identified as being used for brute-force activity or successful authentication with compromised accounts. The FBI has published those indicators to help organizations investigate potential compromise, while cautioning that some infrastructure may have been dynamically or temporarily assigned.
Evidence on how the operators maintained access after an initial compromise was also found. New accounts were created on affected FortiGate devices, with the FBI identifying a number of account names found on victim systems. In some cases, attackers may also have exploited SSH where the port was exposed.
No Responses