Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Mora_001

Also known as: CVE-2024-55591, ransomware

Description

Mora_001 has surfaced as a financially‑motivated threat actor that leverages the well‑known LockBit ecosystem while developing its own SuperBlack variant for data encryption. The group’s operational playbook starts with exploiting two critical, unauthenticated FortiOS CVEs (CVE-2024-55591 and CVE-2025-24472) to elevate privileges on Fortinet FortiGate firewalls. Once privileged access is achieved, the actor immediately deploys SuperBlack ransomware, encrypting files in a manner that mirrors LockBit’s TOX‑ID ransom notes, indicating possible shared command-and-control infrastructure or code reuse. Beyond initial exploitation, Mora_001 establishes persistence through scheduled tasks and cron jobs, using backdoors such as Havex RAT to maintain footholds and facilitate lateral movement. The group often leverages the default fortigate-firewall account and other privileged accounts (Valid Accounts technique) for Credential Access and Privilege Escalation. Their attacks are typically executed against U.S. organizations in critical sectors, implying a targeted approach rather than indiscriminate opportunism. Operationally, the actor exhibits a structured, multi‑stage campaign: initial exploitation → privilege escalation → persistence via scheduled tasks ↔ backdoors ↔ ransomware deployment. The use of LockBit identifiers and shared infrastructure suggests either an affiliate relationship or a splinter cell that borrows code from the broader LockBit threat. Mora_001’s recent campaigns have shown rapid roll‑out after identifying vulnerable FortiOS versions less than 7.0.16, implying that they monitor public advisories to time attacks and exploit zero‑day flaws within weeks of disclosure.

Goals & Targeting

Targeted Sectors

Healthcare
Manufacturing
Government
Defense

Targeted Countries / Regions

US

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Mora_001 is an emerging ransomware group that combines LockBit‑derived encryption (SuperBlack) with opportunistic exploitation of critical Fortinet FortiGate vulnerabilities. The actor targets U.S. health, manufacturing, government and defense organizations, using CVE-2024-55591 and CVE-2025-24472 to gain unauthenticated super_admin access and deploy ransomware. Quick patching of FortiOS devices is vital to stop their operations.

Goals & Targeting

The strategic objective behind Mora_001 appears to be high‑revenue ransomware activity against U.S. entities in the health, manufacturing, government, and defense sectors. The actor’s focus on privileged network devices allows for widespread file access and potential pivot points into deeper enterprise networks. Funding acquisition is likely achieved by ransom payments, with the use of LockBit identifiers facilitating monetization through a proven distribution channel.

Enhanced Description

Key Capabilities

  • Deploy SuperBlack ransomware (LockBit derivative)
  • Exploit Fortinet FortiOS CVE-2024-55591 and CVE-2025-24472 for initial access and privilege escalation via unauthenticated fortigate-firewall account
  • Establish persistence using scheduled tasks/cron jobs
  • Maintain backdoor access through Havex RAT
  • Leverage privileged accounts (Valid Accounts) to move laterally and achieve super_admin rights

MITRE ATT&CK Tactics

Execution
Persistence
Privilege Escalation
Credential Access
Initial Access
Impact

ATT&CK Techniques

T1203
T1078
T1053
T1190
T1486

Software / Tooling

SuperBlack (LockBit derivative)
Havex RAT

Campaigns & Victims

Mora_001 campaigns appear to run in concentrated bursts, targeting networks with known Fortinet FortiGate firewalls running outdated firmware. Following exploitation and privilege escalation, the group swiftly deploys SuperBlack, encrypts critical files, and demands ransom. The use of scheduled tasks and backdoors suggests a preference for stealthy persistence to maintain access over extended periods, enabling them to maximize revenue from each compromised environment.

IOC Patterns

  • FortiOS CVE-2024-55591 exploitation
  • FortiOS CVE-2025-24472 exploitation
  • SuperBlack ransomware payloads
  • Havex RAT backdoor behavior
  • Scheduled tasks or cron job persistence indicators

Recommended Actions

  • Patch Fortinet FortiGate firmware to the latest version (≥7.0.16) as soon as it becomes available, prioritizing the fixes for CVE‑2024‑55591 and CVE‑2025‑24472.
  • Implement network segmentation to isolate firewall devices from critical file shares and reduce lateral movement risk.
  • Enable logging on Fortinet devices and monitor for abnormal authentication attempts using default or privileged accounts.
  • Block outbound connections on known Havex RAT command-and-control IP ranges, and audit scheduled tasks/cron jobs for unauthorized entries.
  • Deploy endpoint detection and response tools that detect encrypted file activity to spot ransomware deployment in real time.
  • Enforce least privilege policies on firewall management interfaces and disable unused administrative ports.

Suggested Tags

ransomware
LockBit
SuperBlack
Fortinet
CVE-2024-55591
CVE-2025-24472
fortigate
Havex RAT
credential dumping
privilege escalation
scheduled task persistence

Confidence Assessment

The analysis is built on publicly documented exploits, malware samples (SuperBlack and Havex RAT), and observed attack patterns. Confidence in the correlation between Mora_001 and FortiOS CVE exploitation is high due to multiple independent reports. However, gaps remain regarding the actor’s full attribution chain, exact persistence mechanisms beyond scheduled tasks, and complete enumeration of compromised sectors and victim counts. Further intelligence (e.g., ransom notes, financial flows) would increase confidence in assessing their operational scope.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 9 MD5 Hash 1 SHA-256 Hash 1 Domain 9

Intel Summary

5

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

4

Tactics

Tags

Ransomware
Lockbit affiliate
Fortinet exploitation
Critical Infrastructure
ransomware
LockBit
SuperBlack
Fortinet
CVE-2024-55591
CVE-2025-24472
fortigate
Havex RAT
credential dumping
privilege escalation
scheduled task persistence

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.