Back Darkreading Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.
A burgeoning ransomware-as-a-service (RaaS) operation is using known exploited vulnerabilities in campaigns against critical infrastructure and government organizations around the globe.
US and South Korean government agencies issued a joint cybersecurity alert on Monday regarding Gunra , a ransomware gang that first emerged in the spring of 2025. Gunra's ransomware is "a sophisticated double-extortion ransomware variant" based on the leaked source code of the now-defunct Conti gang, according to the advisory.
Initially, Gunra operators focused on Windows environments before developing a Linux variant and further expanding operations this year. "As of early 2026, Gunra expanded its operations through a structured RaaS affiliate program advertised on Dark Web forums to financially motivated cybercriminals," the advisory states.
More importantly, the agencies warned, Gunra actors are exploiting N-day vulnerabilities in firewall and VPN appliances for initial access and circumventing some of the most relied-upon defenses for ransomware threats.
According to the advisory, the FBI observed Gunra actors using two known exploited vulnerabilities in Fortinet products for initial access. The first, CVE-2024-55591 , is a critical authentication bypass flaw in FortiOS and FortiProxy that can allow an attacker to achieve "super admin" privileges in Fortinet appliances. The vulnerability was initially disclosed in January 2025 as a zero-day under exploitation.
The second, CVE-2025-24472 , is a high-severity authentication bypass flaw impacting FortiOS and FortiProxy software that was first disclosed in February 2025. CVE-2025-24472 was added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog a month later, following ransomware attacks that weaponized the flaw.
Both Fortinet vulnerabilities have been heavily targeted by ransomware actors since then. For example, an emerging gang known as SuperBlack exploited the two flaws in attacks last year. But despite that attention, it appears that organizations in a variety of sectors and countries have yet to patch the flaws.
Additionally, the FBI observed an attack in which Gunra affiliates took control of an SSL-VPN appliance and used the traffic control functionality to collect credentials and session information for employees authenticating to a corporate virtual desktop infrastructure (VDI) portal. The attackers used the stolen cookies for session hijacking and also leveraged the VDI access to beat the target organization's multifactor authentication protection.
"For the same victim, the Gunra actors modified authentication processing files on the corporate VDI authentication portal server to allow successful authentication when a specific, Gunra-designated one time password (OTP) value was entered, thereby enabling the continuous bypass of multi-factor authentication (MFA)," the advisory stated.
The agencies also cited another attack in which Gunra affiliates deleted backups and archived data stored at both the victim's primary data center and disaster recovery center before and after ransomware was deployed.
In a blog post published Tuesday, Picus Security research engineer Umut Bayram emphasized that the ransomware gang "goes after reusable authentication material at every turn." This includes OS credential dumping and, in one case, compromising a Hiware access control server, stealing the encryption key, and decrypting passwords stored in the database. Therefore, organizations should monitor for suspicious activity around their identity and access management infrastructure.
Gunra attacks have hit a variety of critical infrastructure targets, including organizations in healthcare, financial services, manufacturing, and transportation, as well as government services. According to the advisory, the gang's data leak site lists victims in North and South America, Europe, the Middle East, Africa, and the Asia-Pacific region.
A report published earlier this year by CloudSEK, which infiltrated Gunra's affiliate program to collect intelligence on the gang, showed that Brazil and South Korea were the two most heavily targeted regions, followed by Canada and Japan. CloudSEK researchers also noted the RaaS operation attracts financially motivated but perhaps lower-skilled cybercriminals with ready-made ransomware tools.
"The group significantly lowers the barrier to entry for less-sophisticated threat actors by offering comprehensive affiliate support," the report stated. "This support includes detailed documentation, a user-friendly management panel, and customizable ransomware builders, facilitating the execution of ransomware attacks."
This week's advisory was authored by the FBI, CISA, the US Department of Defense Cyber Crime Center (DC3), the US National Security Agency (NSA), the US Secret Service, and South Korea’s National Police Agency (KNPA). It's unclear where Gunra operators hail from, though a recent report from South Korean cybersecurity firm AhnLab linked the group to a state- threat actor targeting organizations in the country.
"These commonalities suggest that although the state- threat group and the Gunra ransomware group appear to be separate threat actors with different ultimate objectives, they may have shared certain techniques, tools, and infrastructure or collaborated to a limited extent during the attacks," AhnLab's research team wrote in the report.
The joint advisory urged organizations to prioritize patching known exploited vulnerabilities in Internet-facing appliances such as VPNs, implement and test offline immutable backups , and implement network segmentation to limit threat actors' ability to move laterally.
Senior News Director, Dark Reading
Rob Wright is a longtime reporter with more than 25 years of experience as a technology journalist. Prior to joining Dark Reading as senior news director, he spent more than a decade at TechTarget's SearchSecurity in various roles, including senior news director, executive editor and editorial director. Before that, he worked for several years at CRN, Tom's Hardware Guide, and VARBusiness Magazine covering a variety of technology beats and trends.
Prior to becoming a technology journalist in 2000, he worked as a weekly and daily newspaper reporter in Virginia, where he won three Virginia Press Association awards in 1998 and 1999. At TechTarget and Dark Reading, he has won several Azbee awards, including the 2026 National Silver Award for a series on vibe coding.
At Dark Reading, Rob currently covers security operations, cloud security, and Internet infrastructure. He has a keen interest in malvertising activity and the certificate authority industry, and has written extensively on both topics. He graduated from the University of Richmond in 1997 with a degree in journalism and English. A native of Massachusetts, he lives in the Boston area.
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Building a Secure AI Strategy for the Enterprise
Is your AppSec program Mythos Ready?
Experts Explain How to Develop a Framework for Cyber-Fraud Fusion
Prevention at Machine Speed: Hunting Beyond Known Detections
0-Day to 10x Discovery: Security at the Speed of Mythos
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
