Target Industry

Indiscriminate, opportunistic targeting. 

Overview

Between late January and early March 2025, researchers at Forescout identified a new ransomware operator. They observed numerous attacks exploiting two Fortinet vulnerabilities which are being actively exploited in the wild: CVE-2025-24472 and CVE-2024-55591, both with CVSS scores of 8.1. These vulnerabilities were highlighted by the Cybersecurity and Infrastructure Security Agency (CISA) in January 2025. The new ransomware group, Mora_001, uses a modified version of the LockBit ransomware, which has been named SuperBlack. 

Impact

The emergence of the Mora_001 ransomware group has significant implications for cyber security. By exploiting vulnerabilities in Fortinet, threat actors can bypass authentication and gain super admin privileges, facilitating network infiltration. They create persistent, automated administrator accounts that can be recreated if deleted, ensuring long-term access. 

Affected Products

  • FortiOS:  
  • 7.0.0-7.0.16 (fixed in 7.0.17+) 
  • FortiProxy:  
  • 7.0.0-7.0.19 (fixed in 7.0.20+) 
  • 7.2.0-7.2.12 (fixed in 7.2.13+) 

Exploitation

The initial access for SuperBlack ransomware is by exploiting the Fortinet vulnerabilities to bypass authentication and gain super_admin privileges. Once on the network the threat actors use the jsconsole interface or direct HTTPS requests to further exploit the vulnerabilities. The threat actors create persistent administrator accounts with names that blend in with legitimate services.  

Reconnaissance is done using FortiGate dashboards to gather intelligence about the network environment and identify potential paths for lateral movement. VPN user accounts are created with names resembling legitimate accounts to facilitate future access and evade detection. The final step is the development of SuperBlack ransomware, which encrypts critical files and uses wiper malware to erase forensic evidence. 

Containment, Mitigations & Remediations

In accordance with the FortiGuard Labs, it is highly recommended to update the affected versions to the latest release. Within the advisory note the indicators of compromise (IoCs) can be found as well as a workaround on how to disable HTTP/HTTPS administrative interface or how to limit IP addresses that can gain access to the administrative interface. 

Threat Landscape

As a leading provider in the cyber security industry, Fortinet is widely used globally. Recently, there has been a rise in sophisticated cyberattacks from advanced persistent threat (APT) groups exploiting FortiGate vulnerabilities to infiltrate networks. The emergence of SuperBlack ransomware is particularly concerning due to its advanced capabilities and widespread use. 

Threat Group

The Mora_001 ransomware group has been linked to operations involving Russian artifacts, suggesting a possible connection to Russia. Forescout’s research indicates that the SuperBlack ransomware used by Mora_001 shares significant technical similarities with LockBit 3.0. Its exact location remains unclear as they operate through decentralised and covert methods typical of sophisticated ransomware groups.  

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content