VORANT. Threat Intelligence Sign in Get the full feed

INC Ransom claims Gamaus via FortiBleed flaw

elevated threat

The INC Ransom gang added gamaus.com to its leak site after exposed FortiOS SSL-VPN creds via the FortiBleed bug (CVE-2022-40684).

Ransomware.live's tracker logged a new victim, gamaus.com, on the INC Ransom extortion site. The listing notes the target's FortiOS SSL-VPN credentials were previously exposed through the 2022 'FortiBleed' authentication-bypass vulnerability (CVE-2022-40684), suggesting the exposed VPN credentials may have provided the initial access vector used by the intrusion, though the source does not explicitly confirm the exploitation chain.

The entry reports a small externally-visible attack surface (4 assets) and 13 compromised user accounts, with no employee or third-party credential exposure noted. No stolen data samples, ransom note, or additional technical detail beyond the leak-site metadata are provided, limiting confidence in root-cause attribution to the FortiBleed flaw versus other access methods.

This is a routine ransomware-leak-site listing rather than a novel campaign; INC Ransom continues to add victims that had known, unpatched Fortinet SSL-VPN exposure, reinforcing the ongoing risk that unremediated CVE-2022-40684 deployments pose as a foothold for ransomware affiliates.

Mentioned in this report

Vulnerabilities CVE-2022-40684KEV
Threat actors INC Ransom
Malware INC Ransom

Source reporting: https://www.ransomware.live/id/Z2FtYXVzLmNvbUBpbmNyYW5zb20=

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free