- Security Pros places a new Lockbit -Variant in Nature
- A potentially associated abused two tin -faults to implement the encryption
- There are several overlaps with Lockbit 3.0
Lockbit -associated companies are using vulnerable Fortinet -endpoints to target companies with an updated ransomware tribe, experts have warned.
CyberSecurity researchers at SUPPLY found that the threat actor uses two vulnerabilities in the Fortinet Firewalls, the track as CVE-2024-55591, and CVE-20125-24472, to implement an updated ransomware tribe named SuperBlack.
Both vulnerabilities had been used in the past before, and both were patched in January 2025 – so the best way to defend against the attacks is to make sure your Fortinet -Firewalls are up to date.
At least three victims
SUPPLY OUTSIDE The group that ran the attacks “Mora_001”. Since there are some overlaps in its tactics, techniques and procedures (TTP) with Lockbit, the researchers believe the group could be a Lockbit -affiliated company.
Apparently, superblack is based on the developer used in Lockbit 3.0 attacks and leaked in the past. Furthermore, Ransom uses -note in both Lockbit and Mora_001 -strikes the same message address.
Talking to TechcrunchSenior Manager for Threat Hunting at SUPPLY, SAI MELET, said there were at least three confirmed cases, but added that “there could be others”.
Lockbit was one of the most disruptive and influential ransomware groups around, but at the end of February 2024 it was hit by the FBI and it never fully recovered. The law enforcement seized its website, the data it had, and obtained “thousands” of decryption keys.
It also obtained information about its affiliated companies that at that time counted about 200 groups and later called on associated companies to emerge. In February this year, the bulletproof hosting service provider was allegedly used by Lockbit, sanctioned by the United States and the UK.
Lockbit took about a week to get back on their feet and resume operations, but it is possible that many of its affiliated companies were about other groups, such as Ransomhub or Medusa.