VORANT. Threat Intelligence Sign in Get the full feed

Krybit leaks ProHealth Singapore VPN creds

medium threat healthcare

Ransomware group Krybit exposed FortiOS SSL-VPN credentials for Singapore's ProHealth, tied to the 2022 FortiBleed flaw (CVE-2022-40684).

Ransomware.live has indexed a leak entry attributed to the Krybit ransomware operation, listing prohealth.sg (ProHealth Singapore) as a victim. The listing states that the organization's FortiOS SSL-VPN credentials were exposed via the FortiBleed vulnerability, an authentication bypass in Fortinet's FortiOS/FortiProxy administrative interface that was disclosed in 2022 and has been widely abused by multiple threat actors to harvest VPN credentials and gain initial network access.

The entry appears to be a standard victim-shaming leak post rather than a detailed technical disclosure, providing DNS records and a screenshot as proof of compromise. No malware samples, additional infrastructure, or a full description of the intrusion chain following credential theft were provided in the source material. Given the healthcare sector nexus and use of a known, patchable Fortinet vulnerability for initial access, this represents a routine but concerning case of unpatched edge infrastructure being leveraged for ransomware operations.

Mentioned in this report

Vulnerabilities CVE-2022-40684KEV
Threat actors Krybit

Source reporting: https://www.ransomware.live/id/d3d3LnByb2hlYWx0aC5zZ0BrcnliaXQ=

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free