When you purchase through links on our site, we may earn an affiliate commission.Heres how it works.
LockBit affiliates are using vulnerable Fortinet endpoints to target businesses with an updatedransomwarestrain, experts have warned.
At least three victims
Forescout named the group running the attacks Mora_001.
Furthermore, the ransom note in both LockBit and Mora_001 attacks uses the same messaging address.
The law enforcement seized its website, the data it held, and obtained thousands of decryption keys.