{
  "Event": {
    "analysis": "1",
    "date": "2026-06-23",
    "extends_uuid": "",
    "info": "[Threat Intel] Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory",
    "protected": false,
    "publish_timestamp": "1782459195",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1782459195",
    "uuid": "873ebaa8-90f2-4b75-8647-9a7cd02c7f70",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#d2ee74",
        "local": false,
        "name": "misp-galaxy:producer=\"Arctic Wolf\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-original-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#7773ac",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"External Remote Services - T1133\"",
        "relationship_type": ""
      },
      {
        "colour": "#ed66f6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Domain Account - T1087.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Domain Groups - T1069.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#3909cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Automated Collection - T1119\"",
        "relationship_type": ""
      },
      {
        "colour": "#1d736f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Network Sniffing - T1040\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Network Share Discovery - T1135\"",
        "relationship_type": ""
      },
      {
        "colour": "#d40f89",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"AS-REP Roasting - T1558.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#a320c3",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Unsecured Credentials - T1552\"",
        "relationship_type": ""
      },
      {
        "colour": "#041edc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"SMB/Windows Admin Shares - T1021.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Network Device Configuration Dump - T1602.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#6ef296",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Password Spraying - T1110.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#cfba47",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Automated Exfiltration - T1020\"",
        "relationship_type": ""
      },
      {
        "colour": "#f95f85",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol - T1048.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#f5055a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Network Shared Drive - T1039\"",
        "relationship_type": ""
      },
      {
        "colour": "#59699c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"",
        "relationship_type": ""
      },
      {
        "colour": "#492c65",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credential Stuffing - T1110.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#3970d7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote System Discovery - T1018\"",
        "relationship_type": ""
      },
      {
        "colour": "#50bd28",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Network Service Discovery - T1046\"",
        "relationship_type": ""
      },
      {
        "colour": "#f9fe8d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Kerberoasting - T1558.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#110041",
        "local": false,
        "name": "rectifyq:sub-category=\"malware-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#57997c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Bidirectional Communication - T1102.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#3500ca",
        "local": false,
        "name": "rectifyq:detection-rules=\"yara-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356425",
        "to_ids": false,
        "type": "link",
        "uuid": "15712d03-8af6-4c47-9c36-e0c7308078b7",
        "value": "https://arcticwolf.com/resources/blog/inside-fortibleed-reverse-engineering-the-cyberstrike-harvester-behind-a-global-fortigate-credential-factory/"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356425",
        "to_ids": false,
        "type": "text",
        "uuid": "db535cbd-45c6-4a2c-964b-c4c147fa6b80",
        "value": "FortiBleed is a large-scale credential compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways globally. The operation employs a sophisticated credential pipeline utilizing credential stuffing, password spraying, configuration harvesting, offline cracking, and post-authentication capture processing. Reverse engineering of the CyberStrike Harvester v1.5 binary revealed a comprehensive workflow converting FortiGate access into multi-protocol credential extraction, hash cracking via Hashcat/Hashtopolis GPU clusters, VPN-bound Active Directory and SMB access, and file-share exfiltration. The campaign affected devices across 194 countries and uses a seven-VM Kali lab infrastructure with automated tooling including FortiGate Sniffer panels, Telegram-orchestrated cracking bots, and Python/Impacket-based lateral movement tools. One documented exfiltration operation collected 121.43 GB from internal file shares. The operation appears to function as initial-access brokerage wi..."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356425",
        "to_ids": false,
        "type": "text",
        "uuid": "7b06ced5-9997-44ef-b667-26d73b68c646",
        "value": "Name: Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory\nAuthor: AlienVault\nAdversary: \nTags: [\"kerberos\", \"password spraying\", \"ekz infostealer\", \"credential harvesting\", \"fortigate\", \"file exfiltration\", \"hashcat\", \"fortibleed\", \"credential stuffing\", \"ssl vpn\", \"cyberstrike harvester\"]\nTgtd countries: []\nMlwr families: [\"CyberStrike Harvester\", \"EKZ Infostealer\"]\nAttack_ids: [\"T1133\", \"T1539\", \"T1087.002\", \"T1069.002\", \"T1119\", \"T1040\", \"T1135\", \"T1558.004\", \"T1552\", \"T1021.002\", \"T1602.002\", \"T1110.003\", \"T1020\", \"T1552.001\", \"T1048.002\", \"T1039\", \"T1078\", \"T1110.004\", \"T1018\", \"T1046\", \"T1558.003\"]\nIndustries: [\"Government\", \"Telecommunications\", \"Finance\", \"Energy\", \"Healthcare\", \"Education\", \"Manufacturing\", \"Defense\", \"Technology\", \"Retail\", \"Hospitality\", \"Transportation\"]"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356425",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "6ff4a613-2b53-4930-a339-85ba19441159",
        "value": "CVE-2026-35616"
      },
      {
        "category": "Network activity",
        "comment": "Hashtopolis/API endpoint context",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782458004",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "8baa418a-5405-44af-9498-dcf4068fa452",
        "value": "85.11.187.8",
        "Tag": [
          {
            "colour": "#23d92f",
            "local": false,
            "name": "asn:asn=\"25369\"",
            "relationship_type": ""
          },
          {
            "colour": "#0e9e0b",
            "local": false,
            "name": "asn:as-owner=\"BANDWIDTH-AS\"",
            "relationship_type": ""
          },
          {
            "colour": "#e1449b",
            "local": false,
            "name": "asn:as-country=\"GB\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united kingdom\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356425",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "4d873101-1d92-4326-b47b-787ce1e92b18",
        "value": "CVE-2026-0257"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356425",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "29e5b241-36e4-40ee-965c-1cba18c431d8",
        "value": "CVE-2026-25089"
      },
      {
        "category": "Network activity",
        "comment": "SSH exfiltration/staging context",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782458025",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "f3ccc4ec-c082-428d-8482-2685ff4de63d",
        "value": "193.8.187.42",
        "Tag": [
          {
            "colour": "#d60031",
            "local": false,
            "name": "asn:asn=\"214238\"",
            "relationship_type": ""
          },
          {
            "colour": "#34645c",
            "local": false,
            "name": "asn:as-owner=\"IWIHOST\"",
            "relationship_type": ""
          },
          {
            "colour": "#e1449b",
            "local": false,
            "name": "asn:as-country=\"GB\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united kingdom\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "harvest_orig \u2013 CyberStrike Harvester v1.5 No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782456085",
        "to_ids": true,
        "type": "md5",
        "uuid": "ca3d0001-6bdc-4442-8ddf-6898b73de935",
        "value": "7f74bb6ba185978134c318bc5f91d23c",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "harvest_orig \u2013 CyberStrike Harvester v1.5 No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782456086",
        "to_ids": true,
        "type": "sha256",
        "uuid": "7047d4b3-1169-4693-b2a7-7ab2d3c68ce8",
        "value": "2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "ad_enum.py \u2013 LDAP enumeration tooling No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782456087",
        "to_ids": true,
        "type": "sha256",
        "uuid": "e592ac7c-cd78-4632-b7a3-1eeeae1e0409",
        "value": "38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "backup_dfs.py \u2013 SMB/DFS triage collection No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782456088",
        "to_ids": true,
        "type": "sha256",
        "uuid": "bfe60b7a-673c-4764-8f8c-3f20f299c3f5",
        "value": "4253dd1a4c0867b0be7732f75b2f630cebfb7fed94270e15fb3b12ae40546d01",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "bot.py \u2013 Telegram Hashcat bot No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782456089",
        "to_ids": true,
        "type": "sha256",
        "uuid": "6cea775c-0b14-43b1-911d-c83f115a875b",
        "value": "479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "ad_full_audit.py \u2013 LDAP/AD audit tooling No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782456090",
        "to_ids": true,
        "type": "sha256",
        "uuid": "93872f09-d563-4fdd-946e-f97e432532af",
        "value": "874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "backup_dfs2.py \u2013 SMB/DFS full/incremental collection No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782456091",
        "to_ids": true,
        "type": "sha256",
        "uuid": "335b0453-7f43-42e8-8964-082bbfbd9463",
        "value": "9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "On port 8443",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782362968",
        "to_ids": true,
        "type": "ip-dst|port",
        "uuid": "39ef48db-6706-49f8-b43f-6cb6b814a360",
        "value": "85.11.187.8|8443"
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "An object describing a YARA rule (or a YARA rule name) along with its version.",
        "meta-category": "misc",
        "name": "yara",
        "template_uuid": "b5acf82e-ecca-4868-82fe-9dbdf4d808c3",
        "template_version": "7",
        "timestamp": "1782362988",
        "uuid": "c8c63420-32bb-4e2d-bf30-8375c28019a6",
        "Attribute": [
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara-rule-name",
            "timestamp": "1782362988",
            "to_ids": false,
            "type": "text",
            "uuid": "d8a87b70-1779-4ad5-b8ca-b52cd4e7db42",
            "value": "CyberStrike_Harvester_v1_5"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "comment",
            "timestamp": "1782362988",
            "to_ids": false,
            "type": "comment",
            "uuid": "d7c4835e-b52a-4a4f-b228-55799feaeafb",
            "value": "Rule to detect CyberStrike_Harvester_v1.5 using in FortiBleed incident"
          },
          {
            "category": "Payload installation",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "yara",
            "timestamp": "1782362988",
            "to_ids": true,
            "type": "yara",
            "uuid": "03f9b30c-0df2-4603-b0c5-919777468d61",
            "value": "rule CyberStrike_Harvester_v1_5 {\r\nmeta:\r\n        description = \"Rule to detect CyberStrike_Harvester_v1.5 using in FortiBleed incident\"\r\n        author = \"Arctic Wolf\"\r\n        distribution = \"TLP:CLEAR\"\r\n        version = \"1.0\"\r\n        last_modified = \"2026-06-22\"\r\n        sha256 = \"2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98\"\r\n \r\nstrings:\r\n \r\n        $a1 = \"-s HARVEST\" ascii wide\r\n        $a2 = \"ENUMresultsHASHCAT%s\" ascii wide\r\n        $a3 = \"(scan  MB in pacer: % CPU ( zombie\" ascii wide\r\n        $a4 = \"_passwait_userNet\" ascii wide\r\n        $a5 = \"EXTRACTAS-REP/KRB\" ascii wide\r\n \r\n condition:\r\n\r\n    ((uint32(0)==0x464c457f) or\r\n    (uint32(0) == 0xfeedfacf) or (uint32(0) == 0xcffaedfe) or\r\n    (uint32(0) == 0xfeedface) or (uint32(0) == 0xcefaedfe) )  and filesize < 8000KB and (4 of ($a*))\r\n}"
          }
        ]
      }
    ]
  }
}