{
  "type": "bundle",
  "id": "bundle--ecb966d0-93ec-5659-b0a9-ada3e0c40025",
  "objects": [
    {
      "type": "marking-definition",
      "spec_version": "2.1",
      "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
      "created": "2017-01-20T00:00:00.000Z",
      "definition_type": "tlp",
      "name": "TLP:WHITE",
      "definition": {
        "tlp": "white"
      }
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "created": "2026-09-07T00:00:00.000Z",
      "modified": "2026-09-07T00:00:00.000Z",
      "created_by_ref": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ],
      "name": "skopnix",
      "identity_class": "organization",
      "description": "skopnix — open threat intelligence. Aggregated and published, not authored: cite the external_references, not us.",
      "contact_information": "https://skopnix.com"
    },
    {
      "type": "intrusion-set",
      "spec_version": "2.1",
      "created": "2026-09-07T00:00:00.000Z",
      "modified": "2026-09-15T11:55:05.370Z",
      "created_by_ref": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ],
      "id": "intrusion-set--703687c7-bc1f-52ee-9a89-6e6cc23afedc",
      "name": "Mora_001",
      "aliases": [
        "Mora_001"
      ],
      "description": "Mora_001 is a threat actor exhibiting a distinct operational signature that combines opportunistic attacks with ties to the LockBit ecosystem. The actor has been observed exploiting CVE-2024-55591 and CVE-2025-24472 vulnerabilities affecting Fortinet devices. The ransom note associated with Mora_001 includes the same TOX ID used by LockBit, indicating a potential affiliation or shared communication channels. Their post-exploitation patterns suggest a structured playbook that differentiates them from other ransomware operators, including LockBit affiliates.",
      "external_references": [
        {
          "source_name": "skopnix",
          "external_id": "mora-001",
          "url": "https://skopnix.com/actors/mora-001"
        },
        {
          "source_name": "forescout.com",
          "url": "https://www.forescout.com/blog/new-ransomware-operator-exploits-fortinet-vulnerability-duo/"
        }
      ]
    }
  ]
}