C
月内に
FortinetのFortiGate製品を標的とした資格情報窃取キャンペーン「FortiBleed」が、公開から2ヶ月経った現在も継続して脅威となっていること
📌 一言でいうと
FortinetのFortiGate製品を標的とした資格情報窃取キャンペーン「FortiBleed」が、公開から2ヶ月経った現在も継続して脅威となっていることが判明しました。攻撃者は過去に流出したアカウント情報を利用して管理権限やSSL VPNアカウントを奪取し、内部ネットワークへ侵入してNTLMやKerberosなどの認証情報を収集します。これにより、最終的にActive Directoryの侵害やランサムウェア攻撃へと発展させるリスクがあります。
🔍該当判定
- Fortinet社の製品『FortiGate』を導入し、運用している
- FortiGateの『SSL VPN』機能を有効にして外部から社内ネットワークに接続している
- FortiGateの管理画面(管理者アカウント)に、他サービスで使い回しているパスワードを設定している
- FortiGateを導入しており、かつ社内で『Active Directory (AD)』を利用してユーザー管理を行っている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
1. 管理者アカウントおよびSSL VPNアカウントのパスワードを直ちに変更し、強力なパスワードを設定すること。 2. 多要素認証 (MFA) を必須化し、資格情報のみによるログインを防止すること。 3. 管理インターフェースへのアクセス制限(信頼できるIPのみ許可)を徹底すること。 4. 内部ネットワークでの不審な認証トラフィック(NTLM/Kerberos)を監視すること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】FortiGate 資格情報窃取キャンペーン「FortiBleed」への対応について
お疲れさまです。FortiGateを標的とした攻撃キャンペーン「FortiBleed」に関する情報共有です。
■ 概要
過去に流出した資格情報やインフォスティーラーのログを用いて、FortiGateの管理権限およびSSL VPNアカウントを奪取する攻撃が継続して観測されています。侵入後、攻撃者は内部ネットワークでNTLM/Kerberos認証情報を収集し、AD侵害やランサムウェア攻撃へ展開させる傾向があります。
■ 影響範囲
- Fortinet FortiGate (管理インターフェースおよびSSL VPN)
- 特に、他サービスとパスワードを使い回しているアカウント
■ 対応手順
1. 全管理権限アカウントおよびSSL VPNユーザーのパスワード強制リセットの実施
2. 全アカウントへの多要素認証 (MFA) 適用の徹底
3. 管理画面へのアクセスを特定の管理用IPアドレスのみに制限する設定の確認
4. 認証ログにおける不審なログイン試行の確認
■ 参考情報
- Fortinet 公式セキュリティアドバイザリ
対応優先度: 高
対応期限: 直ちに実施
お疲れさまです。FortiGateを標的とした攻撃キャンペーン「FortiBleed」に関する情報共有です。
■ 概要
過去に流出した資格情報やインフォスティーラーのログを用いて、FortiGateの管理権限およびSSL VPNアカウントを奪取する攻撃が継続して観測されています。侵入後、攻撃者は内部ネットワークでNTLM/Kerberos認証情報を収集し、AD侵害やランサムウェア攻撃へ展開させる傾向があります。
■ 影響範囲
- Fortinet FortiGate (管理インターフェースおよびSSL VPN)
- 特に、他サービスとパスワードを使い回しているアカウント
■ 対応手順
1. 全管理権限アカウントおよびSSL VPNユーザーのパスワード強制リセットの実施
2. 全アカウントへの多要素認証 (MFA) 適用の徹底
3. 管理画面へのアクセスを特定の管理用IPアドレスのみに制限する設定の確認
4. 認証ログにおける不審なログイン試行の確認
■ 参考情報
- Fortinet 公式セキュリティアドバイザリ
対応優先度: 高
対応期限: 直ちに実施
Subject: [Security Alert] Response to FortiGate Credential Theft Campaign 'FortiBleed'
Dear IT/Security Team,
This is a technical alert regarding the 'FortiBleed' campaign targeting Fortinet FortiGate devices.
■ Overview
Attackers are leveraging leaked credentials and infostealer logs to gain unauthorized access to FortiGate administrative and SSL VPN accounts. Once access is established, they collect internal authentication tokens (NTLM/Kerberos) to facilitate lateral movement toward Active Directory compromise and ransomware deployment.
■ Scope
- Fortinet FortiGate (Management Interface and SSL VPN)
- Accounts utilizing reused or leaked passwords
■ Mitigation Steps
1. Enforce a mandatory password reset for all administrative and SSL VPN accounts.
2. Ensure Multi-Factor Authentication (MFA) is enabled for all access points.
3. Restrict management interface access to trusted IP addresses only.
4. Monitor authentication logs for anomalous login patterns.
■ Reference
- Fortinet Official Security Advisories
Priority: High
Deadline: Immediate
Dear IT/Security Team,
This is a technical alert regarding the 'FortiBleed' campaign targeting Fortinet FortiGate devices.
■ Overview
Attackers are leveraging leaked credentials and infostealer logs to gain unauthorized access to FortiGate administrative and SSL VPN accounts. Once access is established, they collect internal authentication tokens (NTLM/Kerberos) to facilitate lateral movement toward Active Directory compromise and ransomware deployment.
■ Scope
- Fortinet FortiGate (Management Interface and SSL VPN)
- Accounts utilizing reused or leaked passwords
■ Mitigation Steps
1. Enforce a mandatory password reset for all administrative and SSL VPN accounts.
2. Ensure Multi-Factor Authentication (MFA) is enabled for all access points.
3. Restrict management interface access to trusted IP addresses only.
4. Monitor authentication logs for anomalous login patterns.
■ Reference
- Fortinet Official Security Advisories
Priority: High
Deadline: Immediate