Threat Actor Tied to LockBit Ransomware Targets Fortinet Users post, maart 14, 2025maart 17, 2025 Since January, threat actors have been exploiting two Fortinet vulnerabilities tracked as CVE-2024-55591 and CVE-2025-24472 to deploy SuperBlack ransomware. It’s believed that the threat actor, dubbed “Mora_001” by researchers at Forescout Research–Vedere Labs, is responsible for the attacks that use Russian-language artifacts and other characteristics. Mora_001 is exploiting the two vulnerabilities within FortiOS and FortiProxy in order to gain super-administrator access to vulnerable Fortinet products. Actor Tied to LockBit Ransomware Targets Fortinet Users: Threat Actor Tied to LockBit Ransomware Targets Fortinet Users ransomware 2025