SantaAd is a Russian-speaking initial access broker associated with large-scale acquisition and resale of access to internet-facing enterprise systems, especially Fortinet FortiGate and FortiOS SSL-VPN environments. The actor has been linked to the FortiBleed operation, a broad credential-harvesting and access-brokering campaign that combined internet-wide scanning, brute-force and credential-based intrusion, validation of stolen access, enrichment of victim metadata, and resale-oriented monetization. Reporting characterizes SantaAd as operating in Russian-speaking cybercrime ecosystems and advertising bulk access to compromised Fortinet devices for sale to ransomware operators and other criminal buyers. SantaAd’s activity is centered on obtaining validated remote access at scale rather than deploying bespoke malware for destructive or espionage purposes. Observed tradecraft includes reconnaissance and scanning of exposed services, brute-force and dictionary attacks, use of credentials from prior leaks and infostealer collections, cracking of FortiOS administrative password hashes with rented GPU infrastructure, and abuse of legitimate device functionality for post-compromise credential collection. In Fortinet-focused intrusions, compromised edge devices were reportedly used as passive collection points to capture authentication material traversing the network, including plaintext credentials, Kerberos material, NTLM-related data, and session artifacts. The actor has also been associated with replay of session cookies to maintain or regain access. The operation attributed to SantaAd expanded beyond Fortinet products to include other exposed enterprise technologies such as network-attached storage, firewalls, remote access portals, and database services. Victim data was reportedly enriched with organizational attributes including sector, revenue, and employee count, indicating a brokerage model designed to increase resale value. Available evidence indicates opportunistic, high-volume targeting with particular interest in small and mid-sized organizations and IT service providers, including managed service providers, whose compromise could enable downstream access to customer environments. Post-compromise behavior linked to the broader campaign includes credential harvesting, Active Directory reconnaissance, lateral movement, access to internal file shares, and exfiltration of victim data. SantaAd has been publicly associated with auctions and sale listings for large volumes of Fortinet access on a Russian-speaking underground forum, and has been described as a multi-operator group by some researchers. The dominant assessed motivation is financial gain through access brokerage, including sales to ransomware affiliates and other cybercriminal actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
CVE-2018-13379 was a FortiOS SSL-VPN path traversal flaw that exposed plaintext credentials, and I believe someone collected around 500,000 accounts from that.
Представители Fortinet допускали, что в кампании могли использоваться уязвимости CVE-2026-24858, CVE-2025-59718 и CVE-2025-59719.
Представители Fortinet допускали, что в кампании могли использоваться уязвимости CVE-2026-24858, CVE-2025-59718 и CVE-2025-59719.
Представители Fortinet допускали, что в кампании могли использоваться уязвимости CVE-2026-24858, CVE-2025-59718 и CVE-2025-59719.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker group attributed to the FortiBleed campaign, conducting large-scale credential harvesting and access brokering against internet-facing Fortinet FortiGate and FortiOS SSL-VPN devices.
Русскоязычный брокер первоначального доступа, предположительно связанный с кампанией FortiBleed. Операторы массово сканировали интернет-доступные системы, брутфорсили административные панели, SSL-VPN и SSH, эксплуатировали старые уязвимости FortiGate, устанавливали кастомный сниффер FortigateSniffer и перехватывали учетные данные для последующего использования, перепродажи или передачи другим преступникам.
Financially motivated initial access brokering operation focused on obtaining, validating, cataloging, and reselling Fortinet firewall and remote-access credentials at global scale, likely for resale to ransomware crews.
Initial Access Broker observed selling bulk access to compromised Fortinet devices to ransomware affiliates and other cybercriminals.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.