Threat Actor Tied to LockBit Ransomware Targets Fortinet Users
ID: baae97e1-cafd-563e-a88b-9d60e3f931ae
STIX ID: report--baae97e1-cafd-563e-a88b-9d60e3f931ae
Feed Name: Dark Reading
Date Published: 2025-03-14
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Since January, researchers report a threat actor dubbed Mora_001 is exploiting two Fortinet vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to gain super-administrator access to FortiOS/FortiProxy devices and deploy SuperBlack ransomware; researchers note Russian-language artifacts and possible ties to the LockBit ecosystem and urge organizations—particularly those with exposed FortiGate firewalls—to patch, restrict management access, audit accounts, and enable comprehensive logging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
