logo

New kids on the ransomware block channel Lockbit to raid Fortinet firewalls

ID: 1d2b8cfb-bb21-55db-a750-8c434209c0c5

STIX ID: report--1d2b8cfb-bb21-55db-a750-8c434209c0c5

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2025-03-14

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Researchers identified a new ransomware operator called Mora_001 that leveraged two Fortinet authentication-bypass vulnerabilities to infiltrate devices, create stealthy admin accounts (including HA-synced backdoors and TACACS+/RADIUS-derived persistence), move laterally via SSH to high-value assets, exfiltrate data and deploy a LockBit-derived ransomware variant named SuperBlack; ties to LockBit include shared code and a retained qTox ID. Forescout highlights widespread exposed/unpatched Fortinet devices and recommends patching, auditing admin/VPN accounts, and disabling external management to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.