Russian-speaking FortiGate and Microsoft SQL Server bruteforce campaign
Campaign
Updated: 17.06.2026 18:12
· First: 17.06.2026 18:12
· 📰 1 src / 1 articles
· H score: 82
A Russian-speaking multi-operator threat group ran a FortiGate and Microsoft SQL Server bruteforce campaign that generated billions of credential attempts, raising the risk of widespread account compromise and internal access. The operation targeted 320,777 FortiGate systems and 163,650 SQL Server systems, and recovered credentials were reportedly used for lateral movement into Active Directory environments. The same activity also involved harvesting and cracking SSL VPN hashes, making it a large-scale access-focused intrusion operation.