{"id":542,"date":"2025-03-14T07:18:24","date_gmt":"2025-03-14T07:18:24","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=542"},"modified":"2025-03-17T07:23:01","modified_gmt":"2025-03-17T07:23:01","slug":"threat-actor-tied-to-lockbit-ransomware-targets-fortinet-users","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2025\/03\/14\/threat-actor-tied-to-lockbit-ransomware-targets-fortinet-users\/","title":{"rendered":"Threat Actor Tied to LockBit Ransomware Targets Fortinet Users"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Since January, threat actors have been exploiting two Fortinet vulnerabilities tracked as CVE-2024-55591 and CVE-2025-24472 to deploy SuperBlack ransomware.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It&#8217;s believed that the threat actor, dubbed &#8220;Mora_001&#8221; by researchers at Forescout Research\u2013Vedere Labs, is responsible for the attacks that use Russian-language artifacts and other characteristics. Mora_001 is exploiting the two vulnerabilities within FortiOS and FortiProxy in order to gain super-administrator access to vulnerable Fortinet products.&nbsp;<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2025\/03\/14\/threat-actor-tied-to-lockbit-ransomware-targets-fortinet-users\/\" target=\"_self\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/actor-tied-lockbit-ransomware-targets-fortinet-users\">Actor Tied to LockBit Ransomware Targets Fortinet Users<\/a><span class=\"screen-reader-text\">: Threat Actor Tied to LockBit Ransomware Targets Fortinet Users<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>Since January, threat actors have been exploiting two Fortinet vulnerabilities tracked as CVE-2024-55591 and CVE-2025-24472 to deploy SuperBlack ransomware. It&#8217;s believed that the threat actor, dubbed &#8220;Mora_001&#8221; by researchers at Forescout Research\u2013Vedere Labs, is responsible for the attacks that use Russian-language artifacts and other characteristics. Mora_001 is exploiting the two&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[40],"class_list":["post-542","post","type-post","status-publish","format-standard","hentry","category-ransomware","tag-40"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/542","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=542"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/542\/revisions"}],"predecessor-version":[{"id":543,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/542\/revisions\/543"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}