Uptime Hamster: 10d 15h 0mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Mora_001

Mora_001

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Ver en IntelTracker → APTTrail →
Mora_001 is a newly identified ransomware operator that emerged with a series of intrusions observed between late January and early March 2025, though their exploitation tactics for initial access date back to November 2024. This group is assessed with high confidence to be of Russian origin, indicated by the use of Russian artifacts and Forescout's naming convention for the actor. Their primary motivation is financial gain through ransomware deployments and double extortion schemes. Mora_001 distinguishes itself by rapidly weaponizing and exploiting recently disclosed Fortinet vulnerabilities, specifically CVE-2024-55591 and CVE-2025-24472, to gain initial access. Although they leverage a modified LockBit 3.0 builder to create their "SuperBlack" ransomware, they exhibit a distinct operational signature, employing customized ransom notes and their own data exfiltration tool. Their strong ties to the LockBit ecosystem, potentially as an affiliate or associate, are evidenced by the use o

Actores similares

alp-001actor · 18x001xsransomware · 2ALP-001ransomware · 1
Tecnicas MITRE
T1547 - Boot or Logon Autostart Execution, T1003 - OS Credential Dumping, T1049 - System Network Connections Discovery, T1070 - Indicator Removal on Host, T1190 - Exploit Public-Facing Application, T1529 - System Shutdown/Reboot
CVEs relacionadas
CVE-2025-30066, CVE-2025-24472, CVE-2025-0108, CVE-2024-55591, CVE-2024-41713, CVE-2024-21762
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
28
Actualizado
Sat, 17 Ma

Sectores objetivo (SOCRadar)

Computer Systems Design Services