Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

2 hours ago 2

Rob Wright,

Senior News Director,Dark Reading

August 11, 2026

4 Min Read

A picture of a person using a laptop with a ransomware alert image overlayed.

Source: jittawit.21 via Getty Images

A burgeoning ransomware-as-a-service (RaaS) operation is using known exploited vulnerabilities in campaigns against critical infrastructure and government organizations around the globe.

US and South Korean government agencies issued a joint cybersecurity alert on Monday regarding Gunra, a ransomware gang that first emerged in the spring of 2025. Gunra's ransomware is "a sophisticated double-extortion ransomware variant" based on the leaked source code of the now-defunct Conti gang, according to the advisory.

Initially, Gunra operators focused on Windows environments before developing a Linux variant and further expanding operations this year. "As of early 2026, Gunra expanded its operations through a structured RaaS affiliate program advertised on Dark Web forums to financially motivated cybercriminals," the advisory states.

More importantly, the agencies warned, Gunra actors are exploiting N-day vulnerabilities in firewall and VPN appliances for initial access and circumventing some of the most relied-upon defenses for ransomware threats.

Related:The Coordination Gap: How Attackers Are Outpacing Law Enforcement

Gunra Weaponizing Fortinet Flaws

According to the advisory, the FBI observed Gunra actors using two known exploited vulnerabilities in Fortinet products for initial access. The first, CVE-2024-55591, is a critical authentication bypass flaw in FortiOS and FortiProxy that can allow an attacker to achieve "super admin" privileges in Fortinet appliances. The vulnerability was initially disclosed in January 2025 as a zero-day under exploitation.

The second, CVE-2025-24472, is a high-severity authentication bypass flaw impacting FortiOS and FortiProxy software that was first disclosed in February 2025. CVE-2025-24472 was added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog about a month later, following ransomware attacks that weaponized the flaw.

Both Fortinet vulnerabilities have been heavily targeted by ransomware actors since then. For example, an emerging gang known as SuperBlack exploited the two flaws in attacks last year. But despite that attention, it appears that organizations in a variety of sectors and countries have yet to patch the flaws.

Additionally, the FBI observed an attack in which Gunra affiliates took control of an SSL-VPN appliance and used the traffic control functionality to collect credentials and session information for employees authenticating to a corporate virtual desktop infrastructure (VDI) portal. The attackers used the stolen cookies for session hijacking and also leveraged the VDI access to beat the target organization's multifactor authentication protection.

Related:Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride

"For the same victim, the Gunra actors modified authentication processing files on the corporate VDI authentication portal server to allow successful authentication when a specific, Gunra-designated one time password (OTP) value was entered, thereby enabling the continuous bypass of multi-factor authentication (MFA)," the advisory stated.

The agencies also cited another attack in which Gunra affiliates deleted backups and archived data stored at both the victim's primary data center and disaster recovery center before and after ransomware was deployed.

In a blog post published Tuesday, Picus Security research engineer Umut Bayram emphasized that the ransomware gang "goes after reusable authentication material at every turn." This includes OS credential dumping and, in one case, compromising a Hiware access control server, stealing the encryption key, and decrypting passwords stored in the database. Therefore, organizations should monitor for suspicious activity around their identity and access management infrastructure.

Who's Working with Gunra RaaS?

Gunra attacks have hit a variety of critical infrastructure targets, including organizations in healthcare, financial services, manufacturing, and transportation, as well as government services. According to the advisory, the gang's data leak site lists victims in North and South America, Europe, the Middle East, Africa, and the Asia-Pacific region.

Related:CSS: The Hidden Threat Lurking in Your Inbox

A report published earlier this year by CloudSEK, which infiltrated Gunra's affiliate program to collect intelligence on the gang, showed that Brazil and South Korea were the two most heavily targeted regions, followed by Canada and Japan. CloudSEK researchers also noted the RaaS operation attracts financially motivated but perhaps lower-skilled cybercriminals with ready-made ransomware tools.

"The group significantly lowers the barrier to entry for less-sophisticated threat actors by offering comprehensive affiliate support," the report stated. "This support includes detailed documentation, a user-friendly management panel, and customizable ransomware builders, facilitating the execution of ransomware attacks."

This week's advisory was authored by the FBI, CISA, the US Department of Defense Cyber Crime Center (DC3), the US National Security Agency (NSA), the US Secret Service, and South Korea’s National Police Agency (KNPA). It's unclear where Gunra operators hail from, though a recent report from South Korean cybersecurity firm AhnLab linked the group to a state-sponsored threat actor targeting organizations in the country.

"These commonalities suggest that although the state-sponsored threat group and the Gunra ransomware group appear to be separate threat actors with different ultimate objectives, they may have shared certain techniques, tools, and infrastructure or collaborated to a limited extent during the attacks," AhnLab's research team wrote in the report.

The joint advisory urged organizations to prioritize patching known exploited vulnerabilities in Internet-facing appliances such as VPNs, implement and test offline immutable backups, and implement network segmentation to limit threat actors' ability to move laterally.

Read Entire Article