CyberSecurity SEE

FBI and Secret Service Alert on FortiBleed Lockout Threat

FBI and Secret Service Alert on FortiBleed Lockout Threat

US cybersecurity authorities have issued a critical alert urging administrators of Fortinet firewalls and gateways to enhance security measures as the FortiBleed campaign continues to pose a significant threat. The warning, which was publicized on October 6, is a collaborative effort from the FBI and the US Secret Service, highlighting alarming statistics from SOCRadar indicating that FortiBleed has already compromised an extensive 86,644 devices across 194 nations.

The FortiBleed campaign specifically targets Fortinet’s FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. Notably, ransomware affiliate groups, including INC, Lynx, and Payload, are exploiting the compromised credentials acquired through previous FortiBleed attacks to gain initial access to various systems.

The official notice issued by the authorities indicated that the attackers are actively scanning internet-exposed Fortinet firewalls, utilizing credentials that had been previously compromised. The notice further emphasized the severity of the situation, stating that affected organizations may find themselves locked out of their own systems if attackers manage to disable accounts or alter passwords. In such cases, the necessary remediation steps may extend beyond typical patching and simple password resets, creating an urgent need for further protective measures.

This alarming campaign first came to light in June when a vigilant security researcher uncovered a vast collection of Fortinet usernames and plaintext passwords. The attackers employ automated tools to search for exposed FortiGate SSL VPN portals, effectively leveraging credential stuffing and password spraying tactics. These methods are based on data leaked in previous Fortinet dumps and information stolen from infostealer logs, enabling a systematic approach to gaining unauthorized access.

Upon successfully securing access, the hackers proceed to exfiltrate additional credentials and utilize a powerful “GPU-accelerated cracking cluster” that operates tools such as Hashcat and Hashtopolis to decrypt passwords back into plaintext. The alarming details outlined in the notice further revealed that the cracked credentials would be enriched, sorted, and validated, while scripts sift through honeypots, map organizations, and prioritize high-value targets based on factors such as revenue and network structure. Additionally, attackers create new administrative accounts on the firewall to maintain persistent access within compromised networks.

With verified credentials at their disposal, these cybercriminals gain illegitimate entry into victim environments, where they engage in Active Directory enumeration and password spraying in an effort to expand their access and identify privileged accounts within the network. This methodical intrusion approach underscores the seriousness of the threat FortiBleed represents to organizations worldwide.

In light of this continuing threat, the FBI and Secret Service provided robust guidance to organizations that suspect potential compromise. Their recommendations included isolating compromised hosts by either quarantining or taking them offline, conducting thorough threat hunting efforts to assess the scope of the intrusion, and promptly reporting any compromises to the FBI or Secret Service. Furthermore, organizations are encouraged to utilize the CISA Eviction Strategies Tool to eject the threat actor from their systems.

Additional defensive measures suggested in the advisories include hardening network security by tightening management access, terminating active admin and VPN sessions, resetting credentials, enabling phishing-resistant multi-factor authentication (MFA), and closely reviewing firewall and VPN users as well as configurations for any unauthorized modifications. It is essential as well to thoroughly investigate firewall, VPN, authentication, and domain controller logs for signs of lateral movement within the network and to ensure secure credential storage using robust algorithms like PBKDF2.

Reflecting on the concerning persistence granted to threat actors through the FortiBleed campaign, John Strand, the owner of Black Hills Information Security, expressed grave concerns. He pointed out that while some attackers may aggressively lock down systems and announce their presence, the real danger lies in those who prefer to silently reside within an organization for extended periods. This type of covert access, which FortiBleed facilitates, poses significant risks to the target organization, amplifying the urgency for robust security measures and incident response planning.

In summary, the ongoing FortiBleed campaign continues to threaten global organizations, emphasizing the necessity for administrators to adopt rigorous security practices. The extensive guidance from cybersecurity authorities highlights a proactive approach to safeguarding systems against these insidious attacks.

Source link

Exit mobile version