{"id":3179,"date":"2021-09-09T11:22:59","date_gmt":"2021-09-09T11:22:59","guid":{"rendered":"https:\/\/fortgale.com\/news\/?p=3179"},"modified":"2026-06-08T23:09:29","modified_gmt":"2026-06-08T23:09:29","slug":"fortinet-firewall-italy-compromises","status":"publish","type":"post","link":"https:\/\/fortgale.com\/blog\/emerging-threats\/fortinet-firewall-italy-compromises\/","title":{"rendered":"Fortinet Firewall: compromises in Italy"},"content":{"rendered":"\n<p style=\"text-align: justify\">On the <strong>RAMP<\/strong> underground forum, recently created, a post was published (likely associated with Ransomware Babuk) containing a list of valid credentials (usernames and passwords) for Fortinet VPN access across approximately 13 000 organizations worldwide.<br>The list contains 799 directories and 86 941 presumably compromised VPN sessions. The motivation behind the file sharing remains unclear.<\/p>\n<p style=\"text-align: justify\"><strong>Compromised user accounts on firewalls in Italy represent approximately 8% of the total.<\/strong><\/p>\n<p style=\"text-align: justify\">The following image represents the composition of the attack at demographic level. As can be observed, Italy ranks third.<\/p>\n\n\n<div class=\"wp-block-image caption-align-center is-style-zoooom\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2021\/09\/image-3-1024x667.png\" alt=\"\" class=\"wp-image-3182\" loading=\"lazy\" \/><figcaption class=\"wp-element-caption\">Further details: <a href=\"https:\/\/www.advintel.io\/post\/groove-vs-babuk-groove-ransom-manifesto-ramp-underground-platform-secret-inner-workings\" class=\"ek-link\">LINK<\/a><\/figcaption><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\">Groove Details<\/h4>\n\n\n\n<p>Groove, the platform where the list was actually uploaded, is a new ransomware group that became particularly active between August and September 2021. Groove is presumed to employ former Babuk developers and leverage advanced tactics and tooling. Our <a href=\"https:\/\/fortgale.com\/en\/cybersecurity-advisory\/\">Cybersecurity Advisory<\/a> team has tracked the group&#8217;s infrastructure and operational patterns across multiple campaigns targeting critical infrastructure sectors.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Exploited Vulnerabilities:<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CVE-2019-0708 Bluekeep RDP vulnerability<\/li>\n\n\n\n<li>CVE-2021-27065 Microsoft Exchange server RCE<\/li>\n\n\n\n<li>CVE-2021-26857 Microsoft Exchange server RCE<\/li>\n\n\n\n<li>CVE-2020-0796 &#8211; SMBGhost &#8220;Bluecorona&#8221; RCE vulnerability<\/li>\n\n\n\n<li>CVE-2019-11510 Pulse VPN vulnerability<\/li>\n\n\n\n<li>CVE-2020-0829 Citrix scan vulnerability<\/li>\n\n\n\n<li>CVE-2021-21972 &#8211; vmware scan vulnerability<\/li>\n\n\n\n<li>MS17-010 &#8220;Eternalblue&#8221; vulnerability<\/li>\n\n\n\n<li>CVE-2019-19781 &#8211; Citrix netscaler vulnerability<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Fortinet firewall compromises observed across Italian organisations: leaked credentials, exploitation patterns and remediation priorities.<\/p>\n","protected":false},"author":1,"featured_media":2615,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[3305,1651,3304,3303,1653,3256,1655],"class_list":["post-3179","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-emerging-threats","tag-credential-leak","tag-dump-it","tag-edge-device-compromise","tag-fortigate","tag-fortinet-it","tag-italian-targeting","tag-password-it"],"_links":{"self":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts\/3179","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/comments?post=3179"}],"version-history":[{"count":2,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts\/3179\/revisions"}],"predecessor-version":[{"id":9908,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts\/3179\/revisions\/9908"}],"wp:attachment":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/media?parent=3179"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/categories?post=3179"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/tags?post=3179"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}