SuperBlack is a ransomware strain deployed in intrusions that begin with exploitation of Fortinet FortiOS and FortiGate authentication-bypass vulnerabilities, notably CVE-2024-55591 and CVE-2025-24472. It has been linked to a threat actor tracked as Mora_001 and is assessed to have ties to the LockBit ecosystem. SuperBlack closely resembles LockBit 3.0 (LockBit Black), with reported differences centered on modified ransom-note content and a custom data-exfiltration component, suggesting use of a leaked LockBit builder with operator-specific customization.
Observed SuperBlack operations target internet-exposed Fortinet appliances to obtain administrative access, establish persistence through newly created administrative or VPN-capable accounts, and conduct reconnaissance using firewall configuration data and management dashboards. After gaining a foothold, operators move laterally to high-value systems including file servers, authentication infrastructure, domain controllers, and database servers, using techniques such as WMIC and SSH. In confirmed cases, the operation prioritized data theft before encryption and selectively encrypted file servers rather than indiscriminately encrypting entire environments, consistent with double-extortion ransomware tradecraft.
Victimology associated with SuperBlack includes non-profit, engineering, and financial organizations, with broader reporting also tying activity to attacks against technology-focused targets through related infrastructure. The campaign has been notable for rapid post-compromise execution when conditions are favorable, though operators have also demonstrated longer reconnaissance phases in more defended environments. Reporting also associates the activity with a companion wiper component, WipeBlack, used to remove evidence of ransomware execution and support defense evasion. Overall, SuperBlack represents a Fortinet-exploitation-driven ransomware operation combining opportunistic edge-device compromise, persistence on network infrastructure, lateral movement into core enterprise assets, data exfiltration, and selective encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The second, CVE-2025-24472, is a high-severity authentication bypass flaw impacting FortiOS and FortiProxy software that was first disclosed in February 2025. CVE-2025-24472 was added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog about a month later, following ransomware attacks that weaponized the flaw. | For example, an emerging gang known as SuperBlack exploited the two flaws in attacks last year.
The first, CVE-2024-55591, is a critical authentication bypass flaw in FortiOS and FortiProxy that can allow an attacker to achieve "super admin" privileges in Fortinet appliances. The vulnerability was initially disclosed in January 2025 as a zero-day under exploitation. | For example, an emerging gang known as SuperBlack exploited the two flaws in attacks last year.
"...connected to the operators of a new ransomware strain called SuperBlack..."
"...connected to the operators of a new ransomware strain called SuperBlack..."
"...connected to the operators of a new ransomware strain called SuperBlack..."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It began with the exploitation of Fortigate firewall appliances — culminating in the deployment of a newly discovered ransomware strain we have dubbed SuperBlack. ... The ransomware strain observed in these incidents closely resembles LockBit 3.0 (LockBit Black). The primary differences lie in the ransom note left after encryption and a custom data exfiltration executable. Due to these modifications, we have designated this variant “SuperBlack”.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An emerging ransomware gang mentioned as another actor that exploited the same Fortinet vulnerabilities.
Mentioned only as another ransomware operation using the same vulnerability pattern.
Ransomware strain referenced as being deployed by actors exploiting Fortinet CVE-2024-21762 (authentication bypass) for initial access.
SuperBlack is a ransomware strain that has been deployed by the Mora_001 operator and is linked to the LockBit cybercrime gang. It is used to encrypt files and demand ransom payments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.