Infosecurity

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

Published

on

New Advisory Warns of Gunra’s Double Extortion Campaign

A joint advisory from US and Republic of Korea authorities has put a spotlight on Gunra, a ransomware-as-a-service (RaaS) operation that’s actively targeting government agencies and critical national infrastructure. The warning, published on August 10, details how the group is exploiting two known Fortinet vulnerabilities to gain a foothold in high-value networks.

The advisory comes from the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and other US agencies, alongside South Korea’s National Police Agency (KNPA). It paints a picture of a sophisticated operation that doesn’t just lock files—it steals vast amounts of data first, then demands a hefty ransom.

Gunra’s code traces back to leaked Conti ransomware source code from 2022. The group first appeared in April 2025, but by early 2026 it had structured itself into a proper RaaS affiliate program, advertised on dark web forums. It’s also adopted new branding, sometimes operating under the alias “Golden Community.”

Legacy Fortinet Vulnerabilities Still Effective

The FBI has observed Gunra specifically targeting two legacy Fortinet vulnerabilities. Both are authentication bypass flaws affecting specific versions of FortiOS and FortiProxy.

  • CVE-2024-55591: A critical flaw that lets a remote attacker gain super-admin privileges via crafted requests to the Node.js websocket module.
  • CVE-2025-24472: A high-severity vulnerability allowing a remote unauthenticated attacker, who knows upstream and downstream device serial numbers, to gain super-admin privileges on the downstream device when Security Fabric is enabled, via crafted CSF proxy requests.

Patches are available for both. Yet the advisory notes that victims are still getting hit—often even after applying fixes.

Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, explains why. “Patching fixes the entry point. It does nothing about an authentication backdoor already embedded in the MFA flow. I’ve seen organizations close the vulnerability and declare themselves clean while the attacker’s persistence mechanism sat untouched in the auth stack.”

How Gunra Operates Once Inside

The advisory details several observed techniques. In one case, Gunra actors accessed an administrator account for an SSL-VPN appliance by exploiting default credentials when account lockout controls weren’t in place. They then downloaded OpenSSH to establish connections between compromised systems and an external attacker-controlled server.

In another example, attackers modified authentication processing files on a corporate VDI authentication portal server, enabling them to continuously bypass multi-factor authentication (MFA). These aren’t flashy exploits—they’re quiet, persistent adjustments that let the group move freely.

Stealthy Exfiltration of Massive Data Volumes

Gunra’s approach is built around stealth. The group primarily conducts malicious activities and internal reconnaissance between 10:00 PM and 6:00 AM in the victim’s time zone, when administrators are typically offline. They also delete system and network access logs, and clear command history to hinder detection.

Roman Sannikov, global research coordinator at iCOUNTER, warns security teams to take note. “If your detection coverage drops off overnight, that’s exactly the gap this group, now also operating under the alias Golden Community, is built to exploit.”

The ransomware binary includes filtering rules to focus only on user data files, avoiding wasted encryption resources on non-critical files. The FBI has observed actors using a malicious executable to exfiltrate data from Microsoft OneDrive and SharePoint. In at least one case, they successfully exfiltrated tens of terabytes of data by creating compressed archives and sending them to the file-sharing service Mega.

Ransom Demands in the Tens of Millions

Gunra’s ransom notes typically start negotiations by demanding tens of millions of dollars—a figure the report describes as “arbitrarily high.” Victims get five to seven days to begin negotiations via a Tor-based portal. In some cases, the group has even emailed management staff directly at victim organizations.

If victims don’t engage or pay, the group threatens to publish leaked data on its data leak site. This is classic double extortion: pay to decrypt your files, and pay again to keep your data private.

Victims span regions worldwide and include healthcare, financial services, government organizations, and critical manufacturing sectors.

Defending Against Gunra

The advisory urges organizations to focus on three key areas to counter Gunra’s tactics:

  • Prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure.
  • Implement and test offline, immutable backups stored in a physically separate, segmented location to ensure recoverability without paying a ransom.
  • Segment networks to restrict lateral movement from an initially compromised device to other systems.

The message is clear: this group is patient, stealthy, and well-organized. They’re exploiting known flaws in legacy systems, and they’re doing it under the cover of night. Organizations in critical sectors need to patch fast, monitor around the clock, and assume that MFA alone won’t save them. For more on protecting your infrastructure, check out our guide on ransomware defense strategies for enterprises and learn how to harden VPN gateways against cyberattacks.

The clock is ticking. If you haven’t patched those Fortinet vulnerabilities yet, consider this your wake-up call.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version