How Gunra ransomware is exploiting Fortinet flaws to ransack critical infrastructure

Gunra has launched its own RaaS affiliate program, advertising its offering on dark web hacker forums

Must Read

- Advertisement -
- Advertisement -
  • Exploits flaws in devices to steal credentials, breach networks, and pilfer terabytes of sensitive business data from victim organisations.
  • Primarily gains initial access through the exploitation of known vulnerabilities in internet-facing devices, including firewall and VPN appliances.
  • CISA is urging organisations to prioritise patching known exploited vulnerabilities in internet-facing systems, maintain offline immutable backups, and segment networks to prevent attackers from moving deeper into compromised environments.

A relatively little-known ransomware gang operating under the name Gunra has been quietly yet methodically targeting critical infrastructure sectors around the world, exploiting flaws in Fortinet devices to steal credentials, breach networks, and pilfer terabytes of sensitive business data from victim organisations.

The warning comes from a joint cybersecurity advisory released earlier this week by the US Cybersecurity and Infrastructure Security Agency (CISA) and the FBI, in partnership with South Korea’s National Police Agency.

US authorities say the sophisticated Gunra gang has been targeting organisations across government, healthcare, financial services, manufacturing, transportation, utilities, media, and other critical sectors since at least April 2025.

Wasting no time, by January 2026 the group had already launched its own ransomware-as-a-service (RaaS) affiliate program, advertising its offering on dark web hacker forums.

Affiliates who sign on to the ransomware deal receive their own management panel, a configurable ransomware builder, and access to cross-platform payloads. Operating indiscriminately and regardless of location, the group has been observed targeting organisations across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific region.

The 21-page advisory explains that Gunra ransomware is believed to be based on, or heavily influenced by, the Conti source code that was previously leaked in 2022. Gunra — which has not yet been linked to any country of origin — is said to “primarily gain initial access through the exploitation of known vulnerabilities in internet-facing devices, including firewall and VPN appliances.”

Two catalogued authentication bypass vulnerabilities identified by the FBI — CVE-2024-55591 and CVE-2025-24472 — affect specific versions of Fortinet’s FortiOS and FortiProxy products. South Korean authorities have also observed Gunra exploiting credential exposure and SSH access control vulnerabilities in internet-facing VPN gateways to gain unauthorised remote access.

Stealthy intrusion and lateral movement

The FBI reports that the threat actor has dumped credentials from compromised domain controllers, hijacked legitimate user sessions, and — in at least one case — altered authentication files to continuously bypass multi-factor authentication. The group then moved laterally into critical systems, including Active Directory servers and virtual desktops used by IT personnel.

As part of the gang’s double-extortion strategy and before encrypting victims’ systems, Gunra is known to extract a trove of sensitive files and information, including:

  • Business-critical documents
  • Databases
  • Personally identifiable information (PII)
  • Internal email communications
  • System and network configuration information

The group is further said to encrypt not just individual files, but “key assets, including database servers and network-attached storage (NAS) systems.” In one documented attack, the FBI observed the group exfiltrating victim data directly from Microsoft OneDrive and SharePoint, generating compressed archives, with “the volume of exfiltrated data ranging up to tens of terabytes.”

Once encryption takes place, Gunra threatens to publish or sell the stolen information unless a ransom is paid — typically giving victims five to seven days to negotiate via a Tor-based portal or using qTox, a popular encrypted messaging app among extortion gangs. The FBI says Gunra’s opening ransom demands have reached into the tens of millions of dollars.

Evolving cross-platform capabilities

Initially focused on Windows systems, the FBI says Gunra introduced a Linux variant in mid-2025 as the operation expanded into broader cross-platform attacks. This evolution underscores a familiar reality for defenders: threat actors will use any viable entry point they can find, which means organisations need the visibility and controls to detect and stop an attacker before that initial foothold becomes a full-scale ransomware event.

CISA is urging organisations to prioritise patching known exploited vulnerabilities in internet-facing systems, maintain offline immutable backups, and segment networks to prevent attackers from moving deeper into compromised environments.

Fortinet in the crosshairs

Fortinet products, meanwhile, have faced repeated targeting in recent months. In June, security researchers uncovered a working database containing more than 30,000 verified Fortinet usernames and passwords, said to have been compiled entirely by hackers.

The massive credential-harvesting operation — known as “FortiBleed” — was tied to roughly 75,000 attacks on organisations across 194 countries, including banks, hospitals, telecoms, government agencies, and energy companies, with hackers targeting Fortinet firewalls and VPN gateways to carry out further attacks.

And in December, attackers were observed actively exploiting two other FortiGate authentication bypass flaws — CVE-2025-59718 and CVE-2025-59719 — to steal credentials and access vulnerable devices. It remains unknown whether the Gunra hacking collective was involved in any of those attacks.

Author

  • Naushad K Cherrayil

    A technology and telecom writer and editor with over twenty-nine years of experience in the Gulf region. I started with Indian Express and moved to the Gulf's largest newspaper - Gulf News - for 27 years and with TechRadar Pro Middle East. I have interviewed top tech and telecom leaders across the globe and have attended all major tech shows such as Mobile World Congress, CeBIT, CES, Computex and Global launches.

    View all posts
- Advertisement -

Latest News

UAE renews telecommunications licenses of e& and du for 20 years

The sector is expected to undergo a gradual transition from connected networks to intelligent and autonomous networks in the UAE

Samsung’s SynergyCells buyout: A strategic rebalancing of EV and ESS risk

For Samsung, acquiring full ownership provides more control over capacity, scheduling, product mix, and investment decisions

Google’s Pixel 11 carries a $100 price hike as the AI memory squeeze bites

Google unveils Pixel 11, Pixel 11 Pro, Pixel 11 Pro XL, and the foldable Pixel 11 Pro Fold smartphones
- Advertisement -
- Advertisement -

More Articles

- Advertisement -