Also known as: CVE-2024-55591, ransomware
Mora_001 has surfaced as a financially‑motivated threat actor that leverages the well‑known LockBit ecosystem while developing its own SuperBlack variant for data encryption. The group’s operational playbook starts with exploiting two critical, unauthenticated FortiOS CVEs (CVE-2024-55591 and CVE-2025-24472) to elevate privileges on Fortinet FortiGate firewalls. Once privileged access is achieved, the actor immediately deploys SuperBlack ransomware, encrypting files in a manner that mirrors LockBit’s TOX‑ID ransom notes, indicating possible shared command-and-control infrastructure or code reuse. Beyond initial exploitation, Mora_001 establishes persistence through scheduled tasks and cron jobs, using backdoors such as Havex RAT to maintain footholds and facilitate lateral movement. The group often leverages the default fortigate-firewall account and other privileged accounts (Valid Accounts technique) for Credential Access and Privilege Escalation. Their attacks are typically executed against U.S. organizations in critical sectors, implying a targeted approach rather than indiscriminate opportunism. Operationally, the actor exhibits a structured, multi‑stage campaign: initial exploitation → privilege escalation → persistence via scheduled tasks ↔ backdoors ↔ ransomware deployment. The use of LockBit identifiers and shared infrastructure suggests either an affiliate relationship or a splinter cell that borrows code from the broader LockBit threat. Mora_001’s recent campaigns have shown rapid roll‑out after identifying vulnerable FortiOS versions less than 7.0.16, implying that they monitor public advisories to time attacks and exploit zero‑day flaws within weeks of disclosure.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Mora_001 is an emerging ransomware group that combines LockBit‑derived encryption (SuperBlack) with opportunistic exploitation of critical Fortinet FortiGate vulnerabilities. The actor targets U.S. health, manufacturing, government and defense organizations, using CVE-2024-55591 and CVE-2025-24472 to gain unauthenticated super_admin access and deploy ransomware. Quick patching of FortiOS devices is vital to stop their operations.
Goals & Targeting
The strategic objective behind Mora_001 appears to be high‑revenue ransomware activity against U.S. entities in the health, manufacturing, government, and defense sectors. The actor’s focus on privileged network devices allows for widespread file access and potential pivot points into deeper enterprise networks. Funding acquisition is likely achieved by ransom payments, with the use of LockBit identifiers facilitating monetization through a proven distribution channel.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Mora_001 campaigns appear to run in concentrated bursts, targeting networks with known Fortinet FortiGate firewalls running outdated firmware. Following exploitation and privilege escalation, the group swiftly deploys SuperBlack, encrypts critical files, and demands ransom. The use of scheduled tasks and backdoors suggests a preference for stealthy persistence to maintain access over extended periods, enabling them to maximize revenue from each compromised environment.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is built on publicly documented exploits, malware samples (SuperBlack and Havex RAT), and observed attack patterns. Confidence in the correlation between Mora_001 and FortiOS CVE exploitation is high due to multiple independent reports. However, gaps remain regarding the actor’s full attribution chain, exact persistence mechanisms beyond scheduled tasks, and complete enumeration of compromised sectors and victim counts. Further intelligence (e.g., ransom notes, financial flows) would increase confidence in assessing their operational scope.
No campaigns linked yet.
No observed data linked yet.
5
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
4
Tactics