New kids on the ransomware block channel Lockbit to raid Fortinet firewalls
ID: 1d2b8cfb-bb21-55db-a750-8c434209c0c5
STIX ID: report--1d2b8cfb-bb21-55db-a750-8c434209c0c5
Feed Name: The Register (Security)
Researchers identified a new ransomware operator called Mora_001 that leveraged two Fortinet authentication-bypass vulnerabilities to infiltrate devices, create stealthy admin accounts (including HA-synced backdoors and TACACS+/RADIUS-derived persistence), move laterally via SSH to high-value assets, exfiltrate data and deploy a LockBit-derived ransomware variant named SuperBlack; ties to LockBit include shared code and a retained qTox ID. Forescout highlights widespread exposed/unpatched Fortinet devices and recommends patching, auditing admin/VPN accounts, and disabling external management to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
