logo

'Mora_001' ransomware gang exploiting Fortinet bug spotlighted by CISA in January

ID: afd4d3ff-a668-5fe9-aed3-e0101bae8f77

STIX ID: report--afd4d3ff-a668-5fe9-aed3-e0101bae8f77

Feed Name: The Record from Recorded Future News

Threat Score
78/100

Date Published: 2025-03-17

Date Updated: 2026-05-01

...
...

Researchers and US agencies have observed active exploitation of two Fortinet FortiGate vulnerabilities (CVE-2024-55591 and CVE-2025-24472) by a new ransomware operator, Mora_001, which deploys a LockBit-derived strain called SuperBlack; CISA and Fortinet issued advisories and patches as intrusions targeting exposed FortiGate management interfaces began in late January and continued into March.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.