Gunra Ransomware Targets Hospitals and Governments, Exploits Critical Vulnerabilities

Gunra Ransomware Targets Hospitals and Governments, Exploits Critical Vulnerabilities

First seen 11 Aug 2026, 16:26 UTC BleepingcomputerTechtimesintel.breakglass.techtherecord.media 89% similarity 79.0

Article Content

Browse articles
ThreatCluster

Gunra ransomware, a ransomware-as-a-service derived from Conti code, has attacked at least 51 organizations globally, including hospitals and government agencies. The group exploits critical vulnerabilities in Fortinet firewall products (CVE-2024-55591 and CVE-2025-24472) to gain access. Ransom demands often exceed $10 million, with Linux victims potentially able to recover files without payment due to a cryptographic flaw. The ransomware has been active since April 2025 and has expanded its operations to include a formal RaaS model. A joint advisory from six U.S. and South Korean agencies warns of the ongoing threat and the need for immediate patching of affected systems. Organizations are urged to secure their networks against these sophisticated attacks.

Key Points: • Gunra ransomware has impacted over 51 organizations worldwide, including hospitals and governments. • Attackers exploit critical vulnerabilities in Fortinet products (CVE-2024-55591, CVE-2025-24472) for initial access. • Linux victims may recover encrypted files without paying ransom due to a cryptographic flaw in the ransomware.

ThreatCluster AI How this analysis works

Timeline

2025-01-14
CVE-2024-55591 published
Fortinet disclosed a critical authentication bypass vulnerability in FortiOS.
Techtimes
2025-02-11
CVE-2025-24472 published
Fortinet published a high-severity authentication bypass vulnerability in FortiProxy.
Techtimes
2025-03-18
CVE-2024-55591 added to CISA KEV
CISA confirmed active exploitation of the Fortinet vulnerability in the wild.
Techtimes
2025-04-01
Gunra ransomware first observed
Gunra emerged as a double-extortion ransomware variant derived from the Conti source code.
Bleepingcomputer
2026-01-01
Gunra launches RaaS model
Gunra transitioned to a ransomware-as-a-service model, expanding its operations and recruitment.
Bleepingcomputer
2026-08-11
Joint advisory issued by U.S. and South Korea
Six agencies warned of Gunra ransomware's impact and urged immediate patching of vulnerabilities.
Techtimes

Community

Browse all →