SantaAd is a Russian-speaking initial access broker associated with large-scale credential harvesting and access-brokering activity centered on internet-facing Fortinet FortiGate and FortiOS SSL-VPN systems. The actor has been linked to the FortiBleed campaign, a multi-phase operation that combined internet-wide scanning, brute-force and dictionary attacks, use of credentials from prior leaks and infostealer collections, credential validation, password-hash cracking, and post-compromise traffic interception through legitimate FortiOS packet-sniffing functionality. Reporting also ties the operation to targeting of additional exposed technologies including Synology NAS devices, Sophos firewalls, RDWeb portals, Citrix SSL-VPN, exposed RDP services, and Microsoft SQL Server. SantaAd’s tradecraft is consistent with an access broker focused on obtaining, validating, enriching, and reselling enterprise access rather than conducting a single end-stage intrusion model. Observed workflows included large-scale reconnaissance of exposed services, brute-force attempts against administrative and remote-access interfaces, cracking of recovered authentication material with distributed GPU infrastructure, replay of stolen VPN session material, and follow-on use of recovered credentials for Active Directory reconnaissance, access to internal shares, lateral movement, and data exfiltration. The actor’s infrastructure and victim cataloging reportedly enriched validated access with organization, industry, revenue, and employee-count metadata, indicating prioritization for resale value. Public underground activity attributed to SantaAd included advertising and auctioning Fortinet-related access on a Russian-speaking cybercrime forum and implying responsibility for FortiBleed-related inventory. Victimology appears largely opportunistic at scale, but with notable emphasis on small and mid-sized enterprises, IT providers, managed service providers, and at least some defense-related organizations. The operation has been observed globally across a very large number of countries, with especially prominent targeting in the United States and India. Available reporting characterizes SantaAd primarily as a financially motivated broker whose access could be sold to ransomware operators, espionage actors, or other downstream intruders. Attribution of the FortiBleed campaign specifically to SantaAd has been reported by multiple researchers, but some reporting notes that this linkage has not been independently confirmed by all parties.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
CVE-2018-13379 was a FortiOS SSL-VPN path traversal flaw that exposed plaintext credentials, and I believe someone collected around 500,000 accounts from that.
Представители Fortinet допускали, что в кампании могли использоваться уязвимости CVE-2026-24858, CVE-2025-59718 и CVE-2025-59719.
Представители Fortinet допускали, что в кампании могли использоваться уязвимости CVE-2026-24858, CVE-2025-59718 и CVE-2025-59719.
Представители Fortinet допускали, что в кампании могли использоваться уязвимости CVE-2026-24858, CVE-2025-59718 и CVE-2025-59719.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker group attributed to the FortiBleed campaign, conducting large-scale credential harvesting and access brokering against internet-facing Fortinet FortiGate and FortiOS SSL-VPN devices.
Русскоязычный брокер первоначального доступа, предположительно связанный с кампанией FortiBleed. Операторы массово сканировали интернет-доступные системы, брутфорсили административные панели, SSL-VPN и SSH, эксплуатировали старые уязвимости FortiGate, устанавливали кастомный сниффер FortigateSniffer и перехватывали учетные данные для последующего использования, перепродажи или передачи другим преступникам.
Financially motivated initial access brokering operation focused on obtaining, validating, cataloging, and reselling Fortinet firewall and remote-access credentials at global scale, likely for resale to ransomware crews.
Likely financially motivated initial access broker activity tied to the FortiBleed credential harvesting campaign. The actor is associated with mass scanning and brute-forcing of Fortinet FortiGate VPNs and other edge services, then monetizing validated access by advertising it for sale on Exploit.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.