Critical cybersecurity update: Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA. NetworkFix reviewed the available source material to summarize the security issue, its potential impact and the defensive actions administrators should prioritize.

What Happened

The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances. Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances. Rob Wright , Senior News Director , Dark Reading A burgeoning ransomware-as-a-service (RaaS) operation is using known exploited vulnerabilities in campaigns against critical infrastructure and government organizations around the globe. US and South Korean government agencies issued a joint cybersecurity alert on Monday regarding Gunra , a ransomware gang that first emerged in the spring of 2025. Gunra's ransomware is "a sophisticated double-extortion ransomware variant" based on the leaked source code of the now-defunct Conti gang, according to the advisory. Initially, Gunra operators focused on Windows environments before developing a Linux variant and further expanding operations this year. "As of early 2026, Gunra expanded its operations through a structured RaaS affiliate program advertised on Dark Web forums to financially motivated cybercriminals," the advisory states. More importantly, the agencies warned, Gunra actors are exploiting N-day vulnerabilities in firewall and VPN appliances for initial access and circumventing some of the most relied-upon defenses for ransomware threats.

Technical Details

Related: The Coordination Gap: How Attackers Are Outpacing Law Enforcement According to the advisory, the FBI observed Gunra actors using two known exploited vulnerabilities in Fortinet products for initial access. The first, CVE-2024-55591 , is a critical authentication bypass flaw in FortiOS and FortiProxy that can allow an attacker to achieve "super admin" privileges in Fortinet appliances. The vulnerability was initially disclosed in January 2025 as a zero-day under exploitation. The second, CVE-2025-24472 , is a high-severity authentication bypass flaw impacting FortiOS and FortiProxy software that was first disclosed in February 2025. CVE-2025-24472 was added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog about a month later, following ransomware attacks that weaponized the flaw. Both Fortinet vulnerabilities have been heavily targeted by ransomware actors since then. For example, an emerging gang known as SuperBlack exploited the two flaws in attacks last year. But despite that attention, it appears that organizations in a variety of sectors and countries have yet to patch the flaws. Additionally, the FBI observed an attack in which Gunra affiliates took control of an SSL-VPN appliance and used the traffic control functionality to collect credentials and session information for employees authenticating to a corporate virtual desktop infrastructure (VDI) portal.

Security Impact

Organizations using the affected technology should treat the report according to its critical severity classification. The attackers used the stolen cookies for session hijacking and also leveraged the VDI access to beat the target organization's multifactor authentication protection. The agencies also cited another attack in which Gunra affiliates deleted backups and archived data stored at both the victim's primary data center and disaster recovery center before and after ransomware was deployed. In a blog post published Tuesday, Picus Security research engineer Umut Bayram emphasized that the ransomware gang "goes after reusable authentication material at every turn." This includes OS credential dumping and, in one case, compromising a Hiware access control server, stealing the encryption key, and decrypting passwords stored in the database. Therefore, organizations should monitor for suspicious activity around their identity and access management infrastructure. Gunra attacks have hit a variety of critical infrastructure targets, including organizations in healthcare, financial services, manufacturing, and transportation, as well as government services. According to the advisory, the gang's data leak site lists victims in North and South America, Europe, the Middle East, Africa, and the Asia-Pacific region. CloudSEK researchers also noted the RaaS operation attracts financially motivated but perhaps lower-skilled cybercriminals with ready-made ransomware tools.

Recommended Actions

  • Identify whether the affected product, service or software is present in the environment.
  • Review the original vendor or research advisory and verify affected versions before making configuration changes.
  • Apply vendor-provided security updates or mitigations as soon as operationally practical.
  • Review relevant security logs and monitoring alerts for signs of suspicious activity associated with the reported issue.
  • Use the CVE identifiers, where available, to validate exposure through vulnerability-management and asset-inventory tools.

Security Details

  • Severity: Critical
  • Original source: Dark Reading

Why This Matters

Cybersecurity teams should use reports like this as an input to risk-based vulnerability and threat management rather than relying on headline severity alone. Exposure depends on whether the affected technology is deployed, reachable by an attacker and protected by compensating controls. Confirming asset ownership, affected versions and available vendor fixes helps teams prioritize remediation while avoiding unnecessary emergency changes.

Original Report

NetworkFix recommends reviewing the complete original report from Dark Reading for the authoritative technical context, affected versions, indicators and vendor-specific remediation details: Read the original report.