SuperBlack is an emerging ransomware threat group active by 2025 and associated with exploitation of internet-facing edge infrastructure for initial access, particularly Fortinet appliances. Reporting links the group to exploitation of CVE-2024-55591 in FortiOS and FortiProxy, and to broader use of recently disclosed high-priority vulnerabilities. SuperBlack has been identified as a rising ransomware operation in the post-LockBit and post-ALPHV/BlackCat ecosystem, where affiliates and operators increasingly shift between platforms and reuse common tooling and exploit paths. SuperBlack has been associated with ransomware intrusions targeting multiple sectors, with reporting specifically highlighting financial organizations, non-profit entities, and engineering-related victims. The group has also been referenced alongside other ransomware families exploiting Fortinet authentication bypass vulnerabilities for initial access. Infrastructure linked to SuperBlack activity has been observed through Russian bulletproof hosting services, but available information does not establish a definitive state affiliation. Operationally, SuperBlack is best characterized as a financially motivated ransomware actor that relies on exploitation of public-facing vulnerabilities for initial compromise. Available reporting supports initial-access activity through exploitation, and its classification as a ransomware group supports post-compromise extortion through encryption. Public reporting in the supplied material does not provide high-confidence detail on its full intrusion lifecycle, affiliate structure, or specific extortion model beyond its role as a ransomware operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The first, CVE-2024-55591, is a critical authentication bypass flaw in FortiOS and FortiProxy that can allow an attacker to achieve "super admin" privileges in Fortinet appliances. The vulnerability was initially disclosed in January 2025 as a zero-day under exploitation.
The second, CVE-2025-24472, is a high-severity authentication bypass flaw impacting FortiOS and FortiProxy software that was first disclosed in February 2025. CVE-2025-24472 was added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog about a month later, following ransomware attacks that weaponized the flaw.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another ransomware gang that previously exploited the same Fortinet vulnerabilities.
Named ransomware family associated with exploitation of Fortinet FortiOS CVE-2024-55591 in 2025 ransomware activity.
Referenced only as another ransomware operation that incorporated the same Fortinet vulnerability.
Rising ransomware group; associated with exploitation of Fortinet FortiProxy.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.