• News/
  • https://www.theregister.com/2025/03/14/ransomware_gang_lockbit_ties/

New kids on the ransomware block channel Lockbit to raid Fortinet firewalls

The Register
·
Connor Jones
·
Published Mar 14, 2025
·
Updated

Researchers are tracking a newly discovered ransomware group with suspected links to LockBit after a series of intrusions were reported starting in January. Forescout said the group it's tracking as Mora_001 exploited two Fortinet vulnerabilities to gain an initial foothold in victim environments before securing persistence and ultimately deploying a new ransomware researchers dubbed SuperBlack. Both CVE-2024-55591 and CVE-2025-24472 are authentication bypass vulnerabilities disclosed by Fortinet in January. The former was disclosed first as a zero-day, since exploit activity went back to December 2024, and the latter was added to the advisory after the fact. At the time of CVE-2024-55591's disclosure on January 14, researchers already said criminals were running a "mass exploitation campaign" against the vendor's firewalls. A proof-of-concept (PoC) exploit made its way online on January 27 and within 96 hours, Forescout said, FortiOS was being actively exploited using that PoC as a guide. After gaining an initial foothold, attackers then escalated their privileges to super-admin and created additional admin accounts to secure persistent access. The attackers named these accounts similarly to existing legitimate ones, just with a single added digit appended, and added them to a VPN group to blend in and go unnoticed during casual admin reviews, researchers assume. In cases where victims had no VPN capabilities, attackers would try to gain access to adjacent firewalls using th...

Read full article

Affected Software

2 affected components
Fortinet FortiOS
Fortinet FortiOS

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new ransomware group connected to LockBit that exploits vulnerabilities in Fortinet firewalls.

2

What security implications are discussed in the article?

The article highlights the risks of ransomware attacks on Fortinet devices due to the exploitation of identified vulnerabilities.

3

What software products are affected by this ransomware group?

The ransomware group is specifically targeting Fortinet's FortiOS.

4

When did the reported intrusions by the Mora_001 group begin?

The reported intrusions by the Mora_001 group began in January.

5

Who is tracking the new ransomware group linked to LockBit?

Forescout is the organization currently tracking the new ransomware group identified as Mora_001.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203