SOCRadar Links FortiBleed Campaign to INC and Lynx Ransomware Increasing Exposure
SOCRadar’s Threat Research Unit (STRU) has linked the FortiBleed credential-harvesting campaign to two active ransomware-as-a-service operations, INC Ransom and Lynx, making the exposure much more significant (see post SOCRadar Links FortiBleed Campaign to INC and Lynx Ransomware Increasing Exposure).
An operator tied to FortiBleed’s infrastructure was found actively working negotiation panels for both groups, tying mass FortiGate credential theft directly to ransomware deployment for the first time.
Behind the credential leaks lies a coordinated operation run by the Lynx-INC ransomware group, and the actors are exploiting a previously undisclosed Nextcloud zero-day that our team is actively investigating.
The operators were found leveraging a Nextcloud zero-day to expand access. Investigation is ongoing – full technical details, affected versions, and IOCs will follow in our upcoming report.
Key findings:
- FortiBleed has targeted 430,000+ FortiGate firewalls worldwide via a custom credential-sniffing tool
- STRU identified 200+ additional operational servers beyond the original campaign
- An operator with access to FortiBleed infrastructure was found logged into both INC Ransom and Lynx negotiation panels
- Victim data from FortiBleed overlaps with victims already tracked by INC Ransom
- An internal tracking document reveals an organized, ~20-person operation with a clear division of labor
What we now know
- Ransomware operation: STRU assesses with high confidence that FortiBleed is operated by the Lynx-INC ransomware group. Extensive intelligence has been obtained on the group, including its members.
- Nextcloud zero-day: The actors are exploiting a previously undisclosed Nextcloud zero-day. Our analysis is ongoing.
- Backdoored accounts: Persistent backdoor accounts were found on compromised devices (username: adminin).
- Large-scale sniffing: Traffic sniffing was identified on ~19,000 Fortinet devices. Following SOCRadar’s notifications to affected parties, this number has dropped to ~11,000.
- Infrastructure seizure: 500 servers were seized – including the server Lynx-INC used for ransom negotiations.
- Decryption: Efforts to recover decryption keys are ongoing.
Recent timeline
- 29 Jun 2026 – 9,426 newly identified FortiGate devices found in Lynx-INC’s internal tracking documents, with ransomware deployed against several targets.
- 27 Jun 2026 – FortiBleed formally linked to the Lynx-INC ransomware group.
- 26 Jun 2026 – IoC update: 42 operation servers and 13 files added.
- 25 Jun 2026 – Citrix target list discovered: 29,000 IP addresses and 37 domains, indicating targeting is expanding beyond FortiGate.
- 25 Jun 2026 – IoC update: 19 operation servers and 4 files added.
A detailed report – covering the Lynx-INC operation, the Nextcloud zero-day, and full indicators of compromise will be published later this week or early next week.
July 2, 2026 at 1:02 pm
[…] evidence suggesting the group comprises roughly 20 members with defined roles. bleepingcomputer.com itnerd.blog […]