'Mora_001' ransomware gang exploiting Fortinet bug spotlighted by CISA in January
ID: afd4d3ff-a668-5fe9-aed3-e0101bae8f77
STIX ID: report--afd4d3ff-a668-5fe9-aed3-e0101bae8f77
Feed Name: The Record from Recorded Future News
Threat Score
Researchers and US agencies have observed active exploitation of two Fortinet FortiGate vulnerabilities (CVE-2024-55591 and CVE-2025-24472) by a new ransomware operator, Mora_001, which deploys a LockBit-derived strain called SuperBlack; CISA and Fortinet issued advisories and patches as intrusions targeting exposed FortiGate management interfaces began in late January and continued into March.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
