ZeroHour
The Recordpublished ()ingested

'Mora_001' ransomware gang exploiting Fortinet bug spotlighted by CISA in January

criticalRansomware exploited in the wildimportance 60CVE-2024-55591CVE-2025-24472

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-55591
Unauthenticated Super-Admin Bypass in Fortinet FortiOS and FortiProxy

CVE-2024-55591 is an authentication bypass (CWE-288) in the Node.js websocket module of Fortinet FortiOS and FortiProxy that lets a remote, unauthenticated attacker gain super-admin privileges via crafted websocket requests. It affects FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12, and is trivially triggerable from the network with no user interaction given network access to the management/websocket interface. Successful exploitation gives full super-admin control of the appliance, which attackers can use to pivot, create persistent access, and deploy ransomware. Any organization running the affected FortiOS or FortiProxy versions, especially with admin interfaces reachable from the internet, is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14, and multiple ransomware crews (reported as Gunra, SuperBlack, and Mora_001) are actively exploiting it.

Do: Upgrade all affected systems beyond the vulnerable ranges — FortiOS later than 7.0.16 and FortiProxy later than 7.0.19 / 7.2.12 — following Fortinet's advisory, or apply the vendor's mitigations where upgrades are not possible (per CISA KEV instructions). Restrict access to the admin/websocket interface from the internet, and hunt for unauthorized super-admin accounts and suspicious websocket connections, since ransomware operators are actively exploiting this flaw. Verify device versions and audit logs for signs of compromise before and after patching.

9.898% KEV ransomware
  • Fortinet FortiOS 7.0.0 through 7.0.16
  • Fortinet FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12
large≈48,000+ internet-exposed Fortinet devices per public scans, out of an installed base in the hundreds of thousands
CVE-2025-24472
Authentication Bypass in Fortinet FortiOS and FortiProxy Grants Super-Admin Access

CVE-2025-24472 is an authentication bypass (CWE-288) in the Fortinet Security Fabric of FortiOS and FortiProxy. A remote, unauthenticated attacker who already knows the serial numbers of both the upstream and downstream devices can send crafted CSF proxy requests to gain super-admin privileges on the downstream device; the attack only works where the Security Fabric is enabled, and the need for serial-number knowledge raises attack complexity. An attacker gains full super-admin control of the downstream Fortinet device, which can serve as a foothold for network-wide compromise. Organizations running affected FortiOS 7.0.x or FortiProxy 7.0.x/7.2.x builds with Security Fabric enabled are in scope. The flaw was added to CISA's KEV catalog on 2025-03-18 with known ransomware use, and multiple ransomware groups (including Gunra, SuperBlack, Mora_001 and Qilin operators) have been reported exploiting Fortinet firewall flaws in recent campaigns.

Do: Upgrade FortiOS 7.0.x and FortiProxy 7.0.x/7.2.x deployments to the fixed releases listed in the Fortinet PSIRT advisory for CVE-2025-24472, and identify any devices where the Security Fabric is enabled and serial numbers of peer devices may be discoverable. As interim mitigation, restrict or disable Security Fabric (CSF) connectivity toward untrusted peers and limit access to the CSF proxy handling path. Because the flaw is KEV-listed with known ransomware use, federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use, and all defenders should review device logs for unexpected super-admin sessions and anomalous CSF proxy traffic.

8.17% KEV ransomware
  • Fortinet FortiOS 7.0.0 through 7.0.16
  • Fortinet FortiProxy 7.0.0 through 7.0.19
  • Fortinet FortiProxy 7.2.0 through 7.2.12
masshundreds of thousands of deployed Fortinet appliances plausibly affected; the practical subset is those with Security Fabric enabled
Full article536 words · extracted from therecord.media · click to collapse

Two vulnerabilities impacting Fortinet products are being exploited by a new ransomware operation with ties to the LockBit ransomware group.

Multiple researchers last week spotlighted the exploitation of CVE-2024-55591 and CVE-2025-24472 by a new ransomware group called Mora_001. 

The Cybersecurity and Infrastructure Security Agency (CISA) gave all federal civilian agencies one week to patch CVE-2024-55591 in January — one of the shortest deadlines it has ever issued — and Fortinet said in an advisory that the bug was being exploited in the wild and later added CVE-2025-24472 to the same advisory. 

Cybersecurity firm Forescout Research published a report Wednesday that said between late January and March, their researchers identified a series of intrusions that began with the exploitation of the bugs — which impact Fortigate firewall appliances — and culminated in the deployment of a newly discovered ransomware strain they dubbed SuperBlack.

The strain is being deployed by Mora_001, which Forescout said “blends elements of opportunistic attacks with ties to the LockBit ecosystem.”

LockBit was one of the most devastating ransomware gangs before an international law enforcement operation shuttered many of the tools and systems the operators used. Forescout Research said Mora_001 “leveraged the leaked LockBit builder, modifying the ransom note structure by removing LockBit branding, and employing their own exfiltration tool.”

The ransom note has clues that led incident responders to believe Mora_001 is likely a current LockBit affiliate with unique methods, or an associate of the group that is simply sharing communication channels with LockBit. 

“The ransomware strain observed in these incidents closely resembles LockBit 3.0 (LockBit Black). The primary differences lie in the ransom note left after encryption and a custom data exfiltration executable. Due to these modifications, we have designated this variant ‘SuperBlack’.”

Stefan Hostetler, lead threat intelligence researcher at Arctic Wolf, told Recorded Future News that the group has been exploiting the Fortinet bugs since late January and confirmed that attacks began on February 2.

Fortinet’s patch should cover both vulnerabilities, Hostetler said, but he explained that the latest reports suggest that threat actors are going after the remaining organizations who were unable to apply the patch or harden their firewall configurations when the vulnerability was originally disclosed.

“The threat actor tied to the ransomware campaign described by Forescout appears to be using a familiar set of tools seen in past ransomware activity, while adapting their initial access techniques,” he said.

Fortinet did not respond to a request for comment.

According to Hostetler, numerous groups began creating their own ransomware when the LockBit 3.0 builder leaked in 2022 but the actor identified by Forescout has blended their activity with other tactics and ransom notes used by other groups like BlackCat/ALPHV

Arctic Wolf began observing the targeting of management interfaces on Fortinet FortiGate firewall devices on the public internet in early December. They continued to see targeting before Fortinet published the advisory identifying the zero day.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/mora001-ransomware-gang-exploiting-vulnerability-lockbit