Ransomware Rumble: “Mora_001” Takes a Page from LockBit’s Playbook!

Meet Mora_001, the comedic understudy of LockBit. This fledgling ransomware group pirouetted onto the scene, exploiting Fortinet vulnerabilities to deploy its own flair—SuperBlack. Armed with a tweaked ransom note and a qTox ID, they’re the cyber equivalent of a band covering a classic hit. Stay vigilant, patch up, and don’t be their encore!

Hot Take:

Looks like the ransomware world just can’t get enough of Fortinet! Mora_001 is proving that even cybercriminals have New Year’s resolutions: new exploits, new ransomware, and a fresh approach to blending in like a digital chameleon. Maybe it’s time for a little less “SuperBlack” and a bit more “SuperPatch,” don’t you think?

Key Points:

  • Mora_001 exploits Fortinet vulnerabilities, CVE-2024-55591 and CVE-2025-24472, to deploy SuperBlack ransomware.
  • The ransomware group uses sophisticated techniques to secure persistent access and evade detection.
  • Links to LockBit are suspected due to shared code and communication channels.
  • Thousands of firewalls remain unpatched, leaving systems vulnerable.
  • Forescout emphasizes the need for vigilance in patching and admin account management.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here