กลับไปหน้าข่าวสาร

FBI เตือน FortiBleed แคมเปญ Credential โจมตี FortiGate กว่า 86,644 เครื่องใน 194 ประเทศ

แชร์:

FBI และ U.S. Secret Service ออกคำเตือนร่วมเกี่ยวกับแคมเปญ FortiBleed ที่กำลังโจมตี Fortinet FortiGate Firewall และ SSL VPN ที่เปิดให้เข้าถึงจากอินเทอร์เน็ต โดยมีรายงานว่าอุปกรณ์มากกว่า 86,644 เครื่องใน 194 ประเทศ ได้รับผลกระทบ — สิ่งสำคัญที่ต้องเข้าใจคือ FortiBleed ไม่ใช่ช่องโหว่ CVE ใหม่ แต่เป็นแคมเปญโจมตีโดยอาศัย Credential ที่อ่อนแอ, รั่วไหล หรือซ้ำกัน ซึ่งเชื่อมโยงกับ Ransomware Group INC/Lynx และ Payload


รายละเอียดทางเทคนิค


FortiBleed ไม่ใช่ CVE — แต่เป็น Credential Campaign


  • ▸ Attack Vector หลัก: ผู้โจมตี Scan หา FortiGate SSL VPN Portal ที่เปิดสาธารณะ จากนั้นใช้ Credential จาก Prior Data Leaks, Infostealer Logs และ Password Reuse เพื่อ Login — ไม่ต้องการ Zero-Day หรือ CVE ใหม่ในขั้นตอน Initial Access
  • ▸ Legacy Password Hashing: แคมเปญยังอาศัย FortiOS ที่จัดเก็บ Password Hash ด้วย SHA-256 แบบ Legacy (ไม่ใช่ PBKDF2) — ทำให้สามารถ Crack ด้วย Distributed Infrastructure ได้อย่างมีประสิทธิภาพ ก่อนนำ Credential ที่ Crack ได้ไป Login
  • ▸ Credential Stuffing + Password Spraying: ใช้ Credential Database ที่รวบรวมจาก Multiple Breach Sources ทำ Stuffing ควบคู่กับ Low-Rate Spraying เพื่อหลีกเลี่ยง Lockout Policy


Post-Access Actions


  • ▸ สร้าง Rogue Admin Account: หลัง Login สำเร็จ ผู้โจมตีสร้าง FortiGate Admin Account ใหม่ที่มีชื่อลักษณะ: forticloud-sync, forticloud-tech, fgtsecure, fgtsec, forti_support2, support_fortinet, Technical_support
  • ▸ Enumerate Active Directory: ใช้ VPN Access ค้นหา Privileged Account ใน AD เพื่อเตรียม Lateral Movement เข้าสู่เครือข่ายภายใน
  • ▸ Lock Out Defenders: เปลี่ยน Password, Disable หรือ Delete Admin Account ที่มีอยู่เดิมเพื่อป้องกัน Incident Response — การทำเช่นนี้บ่งชี้ถึง Ransomware Pre-positioning


IOCs และ Infrastructure


  • ▸ IP 45.154.12[.]132 — C2 Server
  • ▸ IP 154.202.59[.]169 — Proxy
  • ▸ IP 103.27.186[.]156 — Proxy
  • ▸ IP 45.155.250[.]158 — Beacon Relay (HTTPS :4332, :4432)
  • ▸ IP 85.11.187[.]8 — Password Cracking Infrastructure
  • ▸ IP 193.8.187[.]2, 193.8.187[.]42 — Related Infrastructure
  • ▸ Account forticloud-sync, fgtsecure — Rogue Admin Accounts
  • ▸ Port 4332, 4432 — Unusual HTTPS Beacon Traffic


เชื่อมโยง Ransomware


  • ▸ FBI/Secret Service ระบุใน Advisory ว่า FortiBleed Activity เชื่อมกับ Initial Access Broker ที่ขาย Access ให้ Ransomware Operations ได้แก่ INC/Lynx และ Payload Ransomware — โมเดลนี้หมายความว่า Compromise จาก FortiBleed อาจตามด้วย Ransomware Attack โดย Group ที่แตกต่างกัน


ผลกระทบที่อาจเกิดขึ้น


  • ▸ ทุกองค์กรที่มี FortiGate Expose บน Internet เสี่ยง: ไม่ต้องรอ CVE ใหม่ — หากยังใช้ Password ที่อ่อนแอ, ซ้ำกัน หรือ Legacy Hash อุปกรณ์ของคุณคือเป้าหมาย; 86,644 เครื่องใน 194 ประเทศคือหลักฐานว่าแคมเปญนี้ Automate ได้กว้างมาก
  • ▸ Ransomware Gateway Risk: การที่ FortiGate ถูก Compromise ทำให้ผู้โจมตีมี VPN Tunnel เข้าถึงเครือข่ายภายใน — เป็น Entry Point ที่สะดวกที่สุดสำหรับ Ransomware Deployment และ Data Exfiltration ก่อนการ Encrypt


สิ่งที่องค์กรควรทำ


  • ▸ ตรวจสอบ Admin Account ทันที: ค้นหา Account ชื่อ forticloud-sync, forticloud-tech, fgtsecure, fgtsec, forti_support2, support_fortinet และ Technical_support บน FortiGate ทุกเครื่อง — Account เหล่านี้คือ IOC ที่ชัดเจนที่สุด
  • ▸ Reset ทุก Credential และ Enforce MFA: Terminate Active Admin และ VPN Session ทั้งหมด → Reset Password ทุก Account → Enable Phishing-Resistant MFA (FIDO2/Hardware Token) สำหรับ Management Interface และ SSL VPN ทุก User
  • ▸ Verify Password Hashing Algorithm: ตรวจสอบว่า FortiOS Admin Account ใช้ PBKDF2 ไม่ใช่ Legacy SHA-256 — หากพบ Legacy Hash ให้ Force Password Reset และ Upgrade FortiOS


แนวทางลดความเสี่ยงระยะยาว


  • ▸ ลด Internet Exposure ของ Management Interface: ย้าย FortiGate Management Interface ออกจาก Public Internet — ใช้ Trusted Host IP Restriction หรือ Local-In Policy ที่อนุญาตเฉพาะ IP ที่รู้จัก; SSL VPN Portal ควรอยู่หลัง MFA ที่แข็งแกร่ง
  • ▸ Credential Hygiene Program: กำหนด Policy ให้ VPN และ Firewall Admin Account มีความยาว Password ขั้นต่ำ 20 ตัวอักษร, ไม่ซ้ำกับ Password อื่นในองค์กร และ Rotate ทุก 90 วัน — ใช้ Privileged Access Management (PAM) Solution ในการจัดการ
  • ▸ Monitor FortiGate Log อย่างต่อเนื่อง: ตั้ง Alert สำหรับ Login สำเร็จจาก IP ที่ไม่คุ้นเคย, การสร้าง Admin Account ใหม่, การเปลี่ยน Configuration และ Traffic HTTPS บน Port 4332/4432
  • ▸ Backup Isolation: เก็บ Backup ใน Isolated Storage ที่ผู้โจมตีไม่สามารถเข้าถึงผ่าน Compromised VPN Credential — Air-Gap Backup คือ Last Line of Defense หาก Ransomware Deploy สำเร็จ


วิเคราะห์ในมุมมองจาก TXEC


FortiBleed เป็นเครื่องเตือนใจที่สำคัญว่า การโจมตีที่อันตรายที่สุดไม่ใช่เสมอไปที่ใช้ช่องโหว่ Zero-Day — แต่เป็นการใช้ Credential ที่อ่อนแอที่องค์กรปล่อยไว้นานหลายปี


ในบริบทของประเทศไทย ภาค Manufacturing, Logistics, Healthcare และ Financial Services ล้วนใช้ FortiGate อย่างแพร่หลายในฐานะ Network Perimeter และ Remote Access Gateway ทีม TXEC เห็นว่าการ Audit FortiGate Admin Account และ Enable MFA เป็นมาตรการที่ทำได้เร็วที่สุดและมีผลมากที่สุดในการรับมือกับแคมเปญนี้โดยตรง