Skip to main content
Mallory
🇷🇺 RU6 malware familiesExploits CVEs in the wild

Mora_001

Also known asMora_001

Mora_001 is a threat actor tracked in reporting as a Russian-origin actor and initial access broker associated with exploitation of Fortinet FortiGate/FortiOS vulnerabilities, particularly CVE-2024-55591 and CVE-2025-24472, to obtain unauthenticated super_admin access on exposed management interfaces. Reporting attributes a series of intrusions from late January to early March to this actor, with activity culminating in deployment of the SuperBlack ransomware, and in one separate February 2026 incident the actor was described as evolving from ransomware operations toward strategic espionage. Mora_001 has been described as exhibiting a consistent operational signature, using Russian-language artifacts, and showing ties to the LockBit ecosystem while being tracked as distinct from LockBit itself. Observed tradecraft includes use of jsconsole and HTTPS exploitation methods against Fortinet devices; creation of recurring local administrator accounts such as forticloud-tech, fortigate-firewall, adnimistrator, admin_support, and forticloud-sync; use of scheduled FortiGate automation objects to recreate backdoor super_admin accounts; creation of lookalike local VPN users with an added digit; downloading firewall configuration files; use of built-in FortiGate dashboards for reconnaissance; propagation of access across HA deployments; attempted abuse of TACACS+ or RADIUS-backed VPN access; and lateral movement to high-value systems including file servers, authentication servers/domain controllers, database servers, and other infrastructure devices. Reporting states the actor primarily used WMIC for remote discovery and execution and SSH for access to additional systems and network devices. Mora_001 has been linked to deployment of SuperBlack ransomware, assessed as closely resembling LockBit 3.0/LockBit Black but with a modified ransom note and a custom data-exfiltration executable. Reporting states the ransom note reused a TOX ID associated with LockBit 3.0, and assesses that Mora_001 may be a LockBit affiliate or associate group sharing communication channels. In at least one confirmed case, the actor exfiltrated data before selectively encrypting file servers rather than encrypting the entire network. A wiper component named WipeBlack has also been associated with this activity. In the February 2026 intrusion dubbed "FortiSync Quasar," Mora_001 was reported deploying Matanbuchus 3.0, Astarion RAT, and SystemBC. Known alias in the provided content: Mora_001.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
  • 🇮🇳 India
  • 🇧🇷 Brazil

Where they're from

Attributed origin per open-source reporting.

  • RU
MITRE ATT&CK

Tradecraft

19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics32 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
3 techniques
T1078×2
Valid Accounts
T1133
External Remote Services
T1190×3
Exploit Public-Facing Application
TA0002
Execution
3 techniques
T1047×2
Windows Management Instrumentation
T1053
Scheduled Task/Job
T1559
Inter-Process Communication
T1559.001
Component Object Model
TA0003
Persistence
6 techniques
T1053
Scheduled Task/Job
T1078×2
Valid Accounts
T1098
Account Manipulation
T1133
External Remote Services
T1136
Create Account
T1136.001
Local Account
T1556
Modify Authentication Process
TA0004
Privilege Escalation
3 techniques
T1053
Scheduled Task/Job
T1078×2
Valid Accounts
T1098
Account Manipulation
TA0005
Stealth
3 techniques
T1027
Obfuscated Files or Information
T1070
Indicator Removal
T1070.004
File Deletion
T1078×2
Valid Accounts
TA0112
Defense Impairment
1 technique
T1556
Modify Authentication Process
TA0006
Credential Access
2 techniques
T1110
Brute Force
T1556
Modify Authentication Process
TA0007
Discovery
2 techniques
T1046
Network Service Discovery
T1082
System Information Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.004×2
SSH
TA0009
Collection
1 technique
T1602
Data from Configuration Repository
T1602.001
SNMP (MIB Dump)
TA0010
Exfiltration
1 technique
T1041×2
Exfiltration Over C2 Channel
TA0040
Impact
1 technique
T1486×2
Data Encrypted for Impact
IOCS

Observables

35 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping19

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal6

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs2

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables35

Domains, IPs, and hashes tied to this actor, refreshed continuously.