Mora_001 is a threat actor tracked in reporting as a Russian-origin actor associated with exploitation of Fortinet FortiOS/FortiGate devices and deployment of the SuperBlack ransomware. Reporting describes the actor as blending opportunistic intrusion activity with ties to the LockBit ecosystem, while being tracked as distinct from LockBit itself. Forescout assessed that Mora_001 likely used a leaked LockBit builder, retained LockBit-like ransom note structure, and reused a TOX ID associated with LockBit 3.0; SuperBlack was described as closely resembling LockBit 3.0 (LockBit Black), with differences including the ransom note and a custom data-exfiltration executable. The actor has also been described in one incident report as evolving from ransomware operations toward strategic espionage. Observed activity includes exploitation of CVE-2024-55591 and CVE-2025-24472 to obtain unauthenticated super_admin access on vulnerable FortiOS devices with exposed management interfaces. Reported post-compromise behavior includes creation of recurring local administrator accounts such as forticloud-tech, fortigate-firewall, adnimistrator, and admin_support; chaining newly created admin accounts; downloading firewall configuration files; modifying configurations; and establishing persistence via FortiGate automation objects to recreate privileged accounts. When VPN functionality was present, the actor created local VPN users resembling legitimate accounts but with an added digit and added them to VPN groups. In HA deployments, the actor forced configuration propagation so backdoor accounts and automation scripts replicated across clustered firewalls. For reconnaissance and lateral movement, Mora_001 was reported to use built-in FortiGate dashboards and configuration data to identify high-value targets including file servers, authentication servers/domain controllers, database servers, and other infrastructure devices. The actor primarily used WMIC for remote discovery and execution and SSH to access additional systems and network devices. In at least one confirmed case, the actor exfiltrated data before selectively encrypting file servers rather than the entire network, consistent with double-extortion behavior. Associated tooling and malware mentioned in reporting include SuperBlack ransomware, WipeBlack, Matanbuchus 3.0, Astarion RAT, and SystemBC. The actor has also been linked to brute-force tooling used against edge authentication services. Reporting observed VPN Brute in Mora_001 activity and linked overlapping infrastructure to a Russian-language brute-force tool targeting RDWeb, PulseSecure, OWA, GlobalProtect, Fortinet, Cisco, F5 BIG-IP, and Citrix. One report explicitly described Mora_001 as an initial access broker observed delivering SuperBlack ransomware. Known aliases directly provided in the content are limited to Mora_001 / mora_001.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Initial Access and Persistence CVE-2024-55591 and CVE-2025-24472 allow unauthenticated attackers to gain super_admin privileges on vulnerable FortiOS devices (<7.0.16) with exposed management interfaces. A proof-of-concept (PoC) exploit was publicly released on January 27, and within 96 hours, we observed active exploitation in the wild using two distinct methods: jsconsole ... HTTPS ...
Initial Access and Persistence CVE-2024-55591 and CVE-2025-24472 allow unauthenticated attackers to gain super_admin privileges on vulnerable FortiOS devices (<7.0.16) with exposed management interfaces... Another common exploitation method we observed involved the threat actor using the fortigate-firewall account to exploit CVE-2025-24472 rather than CVE-2024-55591.
63 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware campaign in which the VPN Brute infrastructure/tooling was observed.
Threat actor linked (by Forescout) to exploitation of Fortinet FortiOS vulnerabilities resulting in deployment of SuperBlack ransomware; infrastructure overlap noted with Proton66-associated IP activity.
Mora_001 is an initial access broker attributed with exploiting Fortinet FortiOS vulnerabilities to deliver the SuperBlack ransomware.
Conducts intrusions via exploitation of FortiGate/FortiOS perimeter devices, establishes persistence (e.g., creating VPN users), performs reconnaissance and lateral movement (WMIC/SSH), exfiltrates data, and deploys a customized ransomware variant (“SuperBlack”) resembling LockBit 3.0; selectively encrypts high-value systems (notably file servers) after exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.