Mora_001

Origin
RU
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:20:40

Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical energy-and-utilities

Context

Mora_001 is a threat actor exhibiting a distinct operational signature that combines opportunistic attacks with ties to the LockBit ecosystem. The actor has been observed exploiting CVE-2024-55591 and CVE-2025-24472 vulnerabilities affecting Fortinet devices. The ransom note associated with Mora_001 includes the same TOX ID used by LockBit, indicating a potential affiliation or shared communication channels. Their post-exploitation patterns suggest a structured playbook that differentiates them from other ransomware operators, including LockBit affiliates.

Exploited vulnerabilities

  • CVE-2024-55591 (vulnerability)
  • CVE-2025-24472 (vulnerability)

Reports & references

  • forescout.com — New Ransomware Operator Exploits Fortinet Vulnerability Duo (report)

External references