SuperBlack is a ransomware strain first reported by Forescout Research – Vedere Labs after intrusions observed from late January to early March 2025. It was deployed after exploitation of Fortinet FortiGate/FortiOS vulnerabilities CVE-2024-55591 and CVE-2025-24472, which can allow unauthenticated attackers to obtain super_admin privileges on vulnerable FortiOS devices with exposed management interfaces. Forescout assessed SuperBlack to be a customized variant closely resembling LockBit 3.0 (LockBit Black), with the main differences being a modified ransom note and a custom data-exfiltration executable. Reporting also notes use of a leaked LockBit builder, removal of LockBit branding, and reuse of a TOX ID associated with LockBit, suggesting ties to the LockBit ecosystem.
The activity was attributed by Forescout to a threat actor tracked as Mora_001, described as an independent actor with ties to LockBit. After compromising FortiGate appliances, the actor established persistence by creating administrative accounts and scheduled automation tasks, created lookalike VPN users, downloaded firewall configurations, used FortiGate dashboards for reconnaissance, and moved laterally using WMIC and SSH. The actor prioritized high-value systems including file servers, domain controllers/authentication servers, database servers, and other infrastructure devices. In at least one confirmed case, SuperBlack operators exfiltrated data before encryption and selectively encrypted file servers rather than the entire network, consistent with double-extortion behavior.
A related component named WipeBlack was identified with hash 917e115cc403e29b4388e0d175cbfac3e7e40ca1742299fbdb353847db2de7c2; it was described as a wiper used to remove evidence of the ransomware executable. Forescout also linked similar ransom notes to sample d9938ac4346d03a07f8ce8b57436e75ba5e936372b9bfd0386f18f6d56902c88. The ransom note reused TOX ID DED25DCB2AAAF65A05BEA584A0D1BB1D55DD2D8BB4185FA39B5175C60C8DDD0C0A7F8A8EC815. Infrastructure associated with Proton66/AS198953 was also linked by Trustwave SpiderLabs to SuperBlack activity, including IP 193.143.1.65, and reporting states attacks led to SuperBlack infections targeting non-profit, engineering, and financial organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024–21762 and CVE-2024–55591: Critical vulnerabilities in Fortinet’s FortiGate and FortiProxy devices, enabling authentication bypass and remote code execution. | This is seen with CVE-2024–55591, which was also incorporated by LockBit and SuperBlack ransomware operations.
Initial Access and Persistence CVE-2024-55591 and CVE-2025-24472 allow unauthenticated attackers to gain super_admin privileges on vulnerable FortiOS devices (<7.0.16) with exposed management interfaces... Another common exploitation method we observed involved the threat actor using the fortigate-firewall account to exploit CVE-2025-24472 rather than CVE-2024-55591. | It began with the exploitation of Fortigate firewall appliances — culminating in the deployment of a newly discovered ransomware strain we have dubbed SuperBlack. ... The ransomware strain observed in these incidents closely resembles LockBit 3.0 (LockBit Black). The primary differences lie in the ransom note left after encryption and a custom data exfiltration executable. Due to these modifications, we have designated this variant “SuperBlack”.
"...connected to the operators of a new ransomware strain called SuperBlack..."
"...connected to the operators of a new ransomware strain called SuperBlack..."
"...connected to the operators of a new ransomware strain called SuperBlack..."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It began with the exploitation of Fortigate firewall appliances — culminating in the deployment of a newly discovered ransomware strain we have dubbed SuperBlack. ... The ransomware strain observed in these incidents closely resembles LockBit 3.0 (LockBit Black). The primary differences lie in the ransom note left after encryption and a custom data exfiltration executable. Due to these modifications, we have designated this variant “SuperBlack”.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as another ransomware operation using the same vulnerability pattern.
Ransomware strain referenced as being deployed by actors exploiting Fortinet CVE-2024-21762 (authentication bypass) for initial access.
SuperBlack is a ransomware strain that has been deployed by the Mora_001 operator and is linked to the LockBit cybercrime gang. It is used to encrypt files and demand ransom payments.
Ransomware that infects organizations by exploiting vulnerabilities in network devices and systems, leading to file encryption and ransom demands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.