FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-55591 | Unauthenticated Super-Admin Bypass in Fortinet FortiOS and FortiProxy CVE-2024-55591 is an authentication bypass (CWE-288) in the Node.js websocket module of Fortinet FortiOS and FortiProxy that lets a remote, unauthenticated attacker gain super-admin privileges via crafted websocket requests. It affects FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12, and is trivially triggerable from the network with no user interaction given network access to the management/websocket interface. Successful exploitation gives full super-admin control of the appliance, which attackers can use to pivot, create persistent access, and deploy ransomware. Any organization running the affected FortiOS or FortiProxy versions, especially with admin interfaces reachable from the internet, is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14, and multiple ransomware crews (reported as Gunra, SuperBlack, and Mora_001) are actively exploiting it. Do: Upgrade all affected systems beyond the vulnerable ranges — FortiOS later than 7.0.16 and FortiProxy later than 7.0.19 / 7.2.12 — following Fortinet's advisory, or apply the vendor's mitigations where upgrades are not possible (per CISA KEV instructions). Restrict access to the admin/websocket interface from the internet, and hunt for unauthorized super-admin accounts and suspicious websocket connections, since ransomware operators are actively exploiting this flaw. Verify device versions and audit logs for signs of compromise before and after patching. | 9.8 | 98% | KEV ransomware |
| large≈48,000+ internet-exposed Fortinet devices per public scans, out of an installed base in the hundreds of thousands | |
| CVE-2025-24472 | Authentication Bypass in Fortinet FortiOS and FortiProxy Grants Super-Admin Access CVE-2025-24472 is an authentication bypass (CWE-288) in the Fortinet Security Fabric of FortiOS and FortiProxy. A remote, unauthenticated attacker who already knows the serial numbers of both the upstream and downstream devices can send crafted CSF proxy requests to gain super-admin privileges on the downstream device; the attack only works where the Security Fabric is enabled, and the need for serial-number knowledge raises attack complexity. An attacker gains full super-admin control of the downstream Fortinet device, which can serve as a foothold for network-wide compromise. Organizations running affected FortiOS 7.0.x or FortiProxy 7.0.x/7.2.x builds with Security Fabric enabled are in scope. The flaw was added to CISA's KEV catalog on 2025-03-18 with known ransomware use, and multiple ransomware groups (including Gunra, SuperBlack, Mora_001 and Qilin operators) have been reported exploiting Fortinet firewall flaws in recent campaigns. Do: Upgrade FortiOS 7.0.x and FortiProxy 7.0.x/7.2.x deployments to the fixed releases listed in the Fortinet PSIRT advisory for CVE-2025-24472, and identify any devices where the Security Fabric is enabled and serial numbers of peer devices may be discoverable. As interim mitigation, restrict or disable Security Fabric (CSF) connectivity toward untrusted peers and limit access to the CSF proxy handling path. Because the flaw is KEV-listed with known ransomware use, federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use, and all defenders should review device logs for unexpected super-admin sessions and anomalous CSF proxy traffic. | 8.1 | 7% | KEV ransomware |
| masshundreds of thousands of deployed Fortinet appliances plausibly affected; the practical subset is those with Security Fabric enabled |
Full article528 words · extracted from therecord.media · click to collapse
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned on Monday. In a cybersecurity advisory, U.S. law enforcement agencies and South Korea’s National Policy Agency spotlighted the ransomware operation that emerged in April 2025 and is built using source code from the Conti ransomware that was leaked in 2022. “Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations,” said Chris Butera, acting executive assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency (CISA). The agencies warned that Gunra actors have been exploiting CVE-2024-55591 and CVE-2025-24472 — two vulnerabilities affecting popular firewall products from Fortinet that CISA previously warned about — to gain privileged access to organizations, allowing them to steal and encrypt data before extorting organizations. Monday’s report included evidence gleaned from several incidents handled by the FBI and South Korea’s police agency. They found the group is targeting the healthcare, financial services and government sectors globally. In most cases, victims were given exorbitant ransom demands that were over $10 million dollars and told they had five to seven days to pay. “The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments with limited success,” the advisory said. Two weeks ago, researchers warned that some tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with Gunra as it targeted South Korean organizations. The FBI said it first observed the ransomware and its leak site in April 2025. By January, Gunra moved to a ransomware-as-a-service model and the group was seen on cybercriminals forums actively recruiting new members. In recent months, the FBI said it saw the group using new aliases, including the name “Golden Community,” as it has expanded and commercialized its platform by recruiting hackers to serve as initial access brokers. The group initially focused on Windows devices but began using a Linux variant that it created. The advisory noted that as of March, researchers found a weakness in Gunra’s Linux variant that allows defenders to “reconstruct the keys using file timestamps and recover files without paying the ransom.” Butera said CISA, the FBI and other agencies are sharing the advisory and other information with government organizations and industry groups to stop the group from continuing its attacks. The advisory comes as industry groups warn that ransomware incidents continue to increase, particularly those targeting critical industrial organizations. The cybersecurity firm Dragos said it identified 1,140 ransomware incidents affecting industrial organizations worldwide in the second quarter of 2026, a 12% increase compared to Q1. At least four of the attacks on industrial organizations last quarter were attributed to Gunra after the group was responsible for eight attacks in Q1.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/ransomware-south-korea-fbi-gunra