Cybercrime
,
Fraud Management & Cybercrime
,
Network Firewalls, Network Access Control
Theat Actor Accessed INC and Lynx Ransom Negotiation Panels

Two prolific ransomware gangs, INC Ransom and Lynx, have been linked to the FortiBleed operation discovered last month that penetrated more than 430,000 FortiGate firewalls to harvest credentials.
See Also: Know Thy Enemy: Threats to Cyber Resilience
An operator inside the attacker infrastructure actively logged into the negotiation panels of both ransomware-as-a-service groups and worked on ransom demands, security firm SOCRadar said.
Data related to victims in FortiBleed’s internal tracking document overlaps with victims in a separately discovered INC Ransom open directory, showing the same targets are being tracked by the operation and the group.
“Analysis of this [FortiBleed] document points to a structured operation of roughly 20 people, with a small core of primary operators driving the majority of high-impact intrusions, supported by dedicated specialists and a back-office layer of junior operators and technical support,” SOCRadar said.
The credential-harvesting campaign exploits devices still exposed to the Fortinet flaws, which were patched five months ago or earlier, to obtain configuration files and decode legacy admin passwords stored inside. Attackers also brute-forced devices with weak passwords.
“The threat actor behind it operates as an Initial Access Broker, using a custom Golang tool called FortigateSniffer to passively intercept authentication traffic by abusing FortiOS’s native diagnose sniffer packet command across two dozen protocols,” SOCRadar said.
The tool’s traffic-monitoring and credential-parsing workflow may have been helped by an open-source, autonomous penetration testing AI agent called CyberStrike, SOCRadar said.
The artificial intelligence security tool can be plugged into any large language model on the market and teach it “OWASP testing methodology, vulnerability patterns, attack chain reasoning and tool orchestration logic.”
INC Ransom is a financially motivated ransomware and data extortion gang active since 2023. The group is known for carefully selecting high-profile targets with substantial financial resources and sensitive data to maximize ransom payments.
The group typically gains initial access through phishing, stolen credentials and exploitation of internet-facing systems from organizations in the industrial, healthcare and education sectors in the United States and Europe, before stealing data and deploying double-extortion.
Lynx, an offshoot of INC Ransom that emerged in 2024, shares 70% similarity in functions and 50% similarity in code with INC. The group focuses on manufacturing, business services, technology and transportation industries, primarily in Western countries.
On attribution, “tooling with comments in the Cyrillic alphabet suggests a possible Russian origin,” SOCRadar said in a white paper. “The identification of high-value victims, including a NATO-aligned defense contractor, also raises the hypothesis of potential collaboration with Russian state-sponsored groups, a known trend across the Russian cybercrime ecosystem.”
SOCRadar found 200 previously unknown attacker-controlled servers, sniffers and scanners after searching through roughly 11,250 FortiGate portals in more than 150 countries. Roughly 50% of all Fortinet firewall devices facing the internet were breached, the FortiBleed dataset showed.
Of the breached devices with administrative access, almost 90% underwent the full attack chain, from VPN compromise to domain controller access and ultimately domain administrator privileges.
At least 12 ransomware attacks were enabled by this access, encrypting hundreds of endpoints across victim organizations, SOCRadar said. The FortiBleed dataset includes Samsung, Accenture and Oracle among thousands of victims, including major government entities and critical infrastructure providers.
The threat actor ranks targets by economic value to determine how exploitation resources should be allocated. SOCRadar found Python scripts that align FortiGate IP addresses with organizations’ revenue, sort a pool of corporate information by revenue and compile a list of high-revenue domains that have not yet been compromised.
After collecting brute-forced credentials, the group cleans the results to produce a deduplicated dataset and exports data into separate username and password files for subsequent analysis.
“The existence of dedicated tooling to separate genuine signals from artifacts generated by their own operations reflects a notable level of operational maturity that has been observed repeatedly throughout the campaign,” SOCRadar said.
