Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks
CISA, FBI, and South Korean agencies warn Gunra ransomware, with 51 victims since April 2025, exploits Fortinet flaws for double-extortion attacks on critical infrastructure.
CISA, the FBI, and South Korean agencies warned of Gunra ransomware attacks targeting healthcare, financial services, government, and professional services worldwide. The Conti-derived operation exploits internet-facing Fortinet FortiOS and FortiProxy flaws CVE-2024-55591 and CVE-2025-24472 for initial access, then deploys double extortion with Salsa20/ChaCha20 encryption and publishes non-payers on a leak site within five to seven days. Ransomware.Live lists 51 victims since April 2025, mostly in South Korea, Brazil, Spain, Thailand, and Hong Kong. The group uses Impacket tools for SMB lateral movement and NTDS credential dumping, tampers with VDI authentication to accept a designated OTP value to bypass MFA, and launched a RaaS affiliate program in January 2026 under the new alias Golden Community.
- Initial access via Fortinet FortiOS/FortiProxy CVE-2024-55591 and CVE-2025-24472, plus phishing.
- Impacket psexec.py and secretsdump.py used for SMB lateral movement and NTDS credential dumping.
- Tampered VDI authentication portal files to accept a Gunra-designated OTP, bypassing MFA; steals session cookies for hijacking.
- Data exfiltrated via OneDrive, SharePoint, and MEGA; encrypts databases and NAS devices.
- Conti-derived RaaS launched January 2026; recruits pentesters as initial access brokers under Golden Community alias.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-55591 | Unauthenticated Super-Admin Bypass in Fortinet FortiOS and FortiProxy CVE-2024-55591 is an authentication bypass (CWE-288) in the Node.js websocket module of Fortinet FortiOS and FortiProxy that lets a remote, unauthenticated attacker gain super-admin privileges via crafted websocket requests. It affects FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12, and is trivially triggerable from the network with no user interaction given network access to the management/websocket interface. Successful exploitation gives full super-admin control of the appliance, which attackers can use to pivot, create persistent access, and deploy ransomware. Any organization running the affected FortiOS or FortiProxy versions, especially with admin interfaces reachable from the internet, is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14, and multiple ransomware crews (reported as Gunra, SuperBlack, and Mora_001) are actively exploiting it. Do: Upgrade all affected systems beyond the vulnerable ranges — FortiOS later than 7.0.16 and FortiProxy later than 7.0.19 / 7.2.12 — following Fortinet's advisory, or apply the vendor's mitigations where upgrades are not possible (per CISA KEV instructions). Restrict access to the admin/websocket interface from the internet, and hunt for unauthorized super-admin accounts and suspicious websocket connections, since ransomware operators are actively exploiting this flaw. Verify device versions and audit logs for signs of compromise before and after patching. | 9.8 | 98% | KEV ransomware |
| large≈48,000+ internet-exposed Fortinet devices per public scans, out of an installed base in the hundreds of thousands | |
| CVE-2025-24472 | Authentication Bypass in Fortinet FortiOS and FortiProxy Grants Super-Admin Access CVE-2025-24472 is an authentication bypass (CWE-288) in the Fortinet Security Fabric of FortiOS and FortiProxy. A remote, unauthenticated attacker who already knows the serial numbers of both the upstream and downstream devices can send crafted CSF proxy requests to gain super-admin privileges on the downstream device; the attack only works where the Security Fabric is enabled, and the need for serial-number knowledge raises attack complexity. An attacker gains full super-admin control of the downstream Fortinet device, which can serve as a foothold for network-wide compromise. Organizations running affected FortiOS 7.0.x or FortiProxy 7.0.x/7.2.x builds with Security Fabric enabled are in scope. The flaw was added to CISA's KEV catalog on 2025-03-18 with known ransomware use, and multiple ransomware groups (including Gunra, SuperBlack, Mora_001 and Qilin operators) have been reported exploiting Fortinet firewall flaws in recent campaigns. Do: Upgrade FortiOS 7.0.x and FortiProxy 7.0.x/7.2.x deployments to the fixed releases listed in the Fortinet PSIRT advisory for CVE-2025-24472, and identify any devices where the Security Fabric is enabled and serial numbers of peer devices may be discoverable. As interim mitigation, restrict or disable Security Fabric (CSF) connectivity toward untrusted peers and limit access to the CSF proxy handling path. Because the flaw is KEV-listed with known ransomware use, federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use, and all defenders should review device logs for unexpected super-admin sessions and anomalous CSF proxy traffic. | 8.1 | 7% | KEV ransomware |
| masshundreds of thousands of deployed Fortinet appliances plausibly affected; the practical subset is those with Security Fabric enabled |
Full article1,261 words · extracted from thehackernews.com · click to collapse
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world.
Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services.
"Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations," CISA Acting Executive Assistant Director for Cybersecurity, Chris Butera, said.
Attacks deploying the ransomware have leveraged security flaws in internet-facing Fortinet FortiOS and FortiProxy (CVE-2024-55591 and CVE-2025-24472) appliances to obtain initial access, and then deploy the Gunra ransomware as part of a double extortion model that combines data exfiltration and data encryption for maximum impact.
Victims who refuse to pay up within five to seven days have their data published on a data leak site. According to data published on Ransomware.Live, Gunra has listed a total of 51 victims since emerging in the threat landscape in April 2025, with most of them from South Korea, Brazil, Spain, Thailand, and Hong Kong.
What's notable about the threat actor is that the majority of the targets are located in Australia, East Asia, and Europe. Only three victims have been reported from Canada and the U.S. so far.
"The group uses phishing as a main attack vector to deliver malicious pieces to their targets and carry out negotiations on a WhatsApp-themed chat Panel," security researcher Rakesh Krishnan said in an analysis published last year. "The group is capable of encrypting huge files (9TB) in a limited timeframe by using advanced stream cipher encryption such as Salsa20 or ChaCha20."
The Conti-derived operation is said to have launched a formal RaaS affiliate program on dark web forums in January 2026, providing affiliates with access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation.
The group offers both Windows and Linux variants of its locker, although an analysis released by Breakglass Intelligence in March 2026 identified a "catastrophic cryptographic weakness" in the Linux builds that made it possible to recover the encryption key and regain access to the files.
Per the U.S. Federal Bureau of Investigation (FBI), Gunra has been observed adopting new branding aliases, such as Golden Community, to expand its operations, while simultaneously taking steps to monetize its platform by recruiting penetration testers and ethical hackers to serve as initial access brokers, who are offered a share of the ransom profits in exchange for enterprise network access.
Attack chains are known to leverage Impacket libraries "psexec.py" and "smbclient.py" for lateral movement using the Server Message Block (SMB) protocol. Another Impacket utility, "secretsdump.py," is used to conduct credential dumping against compromised domain controllers and extract password hashes of user accounts from the NT Directory Services (NTDS) file.
To cover up traces of malicious activity, the group is known to delete system/network access logs, clear command history, and primarily conduct malicious activities and internal infrastructure reconnaissance between 10 p.m. and 6 a.m. Data exfiltration from Microsoft OneDrive and SharePoint is accomplished by means of an executable named "main.exe."
In select cases, the threat actors have been observed creating compressed archives containing terabytes of data and exfiltrating them to the MEGA file-sharing service. Besides collecting business-critical documents, the group is said to have connected to the virtual desktop infrastructure (VDI) environments of IT personnel and harvested sensitive documents containing system and network configuration information.
"The Gunra actors then leveraged enterprise server credentials stolen from a system access control server to deploy ransomware to encrypt key assets, including database servers and network-attached storage (NAS) systems," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said.
In one case spotted by South Korea's National Police Agency (KNPA), the attackers have been spotted manipulating the network traffic control functionality of an SSL-VPN appliance to intercept credentials and session information transmitted by users authenticating to a corporate VDI authentication portal. These stolen session cookies were then used to conduct session hijacking and impersonate legitimate users to gain access to the internal network.
To bypass multi-factor authentication (MFA), Gunra is said to have tampered with the authentication processing files on the corporate VDI authentication portal server such that it enabled successful authentication when a specific, Gunra-designated one-time password (OTP) value was entered.
Some of the other detected behaviors are listed below -
- Gaining access to an administrator account for an SSL-VPN appliance by exploiting default credentials and then downloading OpenSSH from an attacker-controlled server to set up connections between compromised systems and maintain persistence within the victim environment.
- Relying on an unused account identified in the SSL-VPN administrative web console that had access to both the internet and internal corporate network, and modifying its configuration to sidestep the mandatory password change requirement and empty it for follow-on activities.
- Accessing a Hiware system access control server via SSH from a compromised virtual desktop and stealing a symmetric encryption key stored on the server so as to decrypt passwords for enterprise server accounts stored within the database and perform credential dumping of credentials associated with all enterprise servers.
- Deleting backup and archived data stored on backup infrastructure at both the primary data center and disaster recovery center before and after the ransomware deployment.
The disclosure assumes significance in the face of a recent advisory from South Korea about a cyber campaign orchestrated by an unspecified state-sponsored threat group from 2025 through the first half of 2026 by exploiting vulnerabilities in an unidentified financial security software to distribute malware after tricking victims into visiting malicious URLs through spear-phishing and watering hole techniques.
Interestingly, some of these incidents have also involved the exploitation of the same financial security software vulnerabilities to deploy Gunra ransomware and exfiltrate sensitive organizational information.
Some of the watering hole attacks, per ENKI, have also exploited a zero-day vulnerability in AnySign4PC, causing malware to be installed and executed on systems with the certificate signing software installed when accessing the web page containing the exploit code. Some of the payloads distributed as part of the whole campaign include Struggle (aka SIGNBT 3.0) and Brandoor (aka COPPERHEDGE), both of which are known to be used by the Lazarus Group.
"These commonalities suggest that although the state-sponsored threat group and the Gunra ransomware group appear to be separate threat actors with different ultimate objectives, they may have shared certain techniques, tools, and infrastructure or collaborated to a limited extent during the attacks," AhnLab said.
While the exact origins of Gunra are unclear, this kind of collaboration between a North Korean nation-state group and a ransomware actor is not unheard of. As far back as October 2024, Palo Alto Networks Unit42 said it observed the Lazarus sub-cluster Andariel partnering with the Play ransomware crew.
Andariel itself has a track record of deploying custom ransomware families like SHATTEREDGLASS, Maui, and H0lyGh0st in the past. At least since September 2025, the Lazarus Group and its related intrusion set Moonstone Sleet (aka Storm-1789) have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
To secure against Gunra ransomware, organizations are advised to keep all operating systems, software, and firmware up to date, prioritize patching known exploited vulnerabilities in internet-facing systems, enforce network segmentation, and ensure backups are immutable and stored in a physically separate location.
(A previous version of the story incorrectly mentioned CVE-2024-5559 was exploited in Gunra ransomware attacks. The correct CVE is CVE-2024-55591. The error is regretted.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html