Mora_001
0 incidentes
0 paises
0 sectores
apt RU Ultimo: -
Mora_001 is a newly identified ransomware operator that emerged with a series of intrusions observed between late January and early March 2025, though their exploitation tactics for initial access date back to November 2024. This group is assessed with high confidence to be of Russian origin, indicated by the use of Russian artifacts and Forescout's naming convention for the actor. Their primary motivation is financial gain through ransomware deployments and double extortion schemes. Mora_001 distinguishes itself by rapidly weaponizing and exploiting recently disclosed Fortinet vulnerabilities, specifically CVE-2024-55591 and CVE-2025-24472, to gain initial access. Although they leverage a modified LockBit 3.0 builder to create their "SuperBlack" ransomware, they exhibit a distinct operational signature, employing customized ransom notes and their own data exfiltration tool. Their strong ties to the LockBit ecosystem, potentially as an affiliate or associate, are evidenced by the use o
Sectores objetivo (SOCRadar)
Computer Systems Design Services