Critical cybersecurity update: Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks. NetworkFix reviewed the available source material to summarize the security issue, its potential impact and the defensive actions administrators should prioritize.
What Happened
warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks Reach out to get featured—contact us to send your exclusive story idea, research, hacks, or ask us a question or leave a comment/feedback! Ravie Lakshmanan Aug 11, 2026 Ransomware / Threat Intelligence Cybersecurity and intelligence agencies from South Korea and the U.S. "Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations," CISA Acting Executive Assistant Director for Cybersecurity, Chris Butera, said. Attacks deploying the ransomware have leveraged security flaws in internet-facing Schneider Electric PowerLogic P5 ( CVE-2024-5559 ) and Fortinet FortiOS and FortiProxy ( CVE-2025-24472 ) appliances to obtain initial access, and then deploy the Gunra ransomware as part of a double extortion model that combines data exfiltration and data encryption for maximum impact. According to data published on Ransomware.Live, Gunra has listed a total of 51 victims since emerging in the threat landscape in April 2025, with most of them from South Korea , Brazil, Spain, Thailand, and Hong Kong.
Technical Details
What's notable about the threat actor is that the majority of the targets are located in Australia, East Asia, and Europe. "The group uses phishing as a main attack vector to deliver malicious pieces to their targets and carry out negotiations on a WhatsApp-themed chat Panel," security researcher Rakesh Krishnan said in an analysis published last year. "The group is capable of encrypting huge files (9TB) in a limited timeframe by using advanced stream cipher encryption such as Salsa20 or ChaCha20." The Conti-derived operation is said to have launched a formal RaaS affiliate program on dark web forums in January 2026, providing affiliates with access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation. Another Impacket utility, "secretsdump.py," is used to conduct credential dumping against compromised domain controllers and extract password hashes of user accounts from the NT Directory Services (NTDS) file. Data exfiltration from Microsoft OneDrive and SharePoint is accomplished by means of an executable named "main.exe." In select cases, the threat actors have been observed creating compressed archives containing terabytes of data and exfiltrating them to the MEGA file-sharing service. "The Gunra actors then leveraged enterprise server credentials stolen from a system access control server to deploy ransomware to encrypt key assets, including database servers and network-attached storage (NAS) systems," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said. In one case spotted by South Korea's National Police Agency (KNPA), the attackers have been spotted manipulating the network traffic control functionality of an SSL-VPN appliance to intercept credentials and session information transmitted by users authenticating to a corporate VDI authentication portal. Some of the other detected behaviors are listed below – Gaining access to an administrator account for an SSL-VPN appliance by exploiting default credentials and then downloading OpenSSH from an attacker-controlled server to set up connections between compromised systems and maintain persistence within the victim environment.
Security Impact
Organizations using the affected technology should treat the report according to its critical severity classification. Accessing a Hiware system access control server via SSH from a compromised virtual desktop and stealing a symmetric encryption key stored on the server so as to decrypt passwords for enterprise server accounts stored within the database and perform credential dumping of credentials associated with all enterprise servers. Deleting backup and archived data stored on backup infrastructure at both the primary data center and disaster recovery center before and after the ransomware deployment. The disclosure assumes significance in the face of a recent advisory from South Korea about a cyber campaign orchestrated by an unspecified state-sponsored threat group from 2025 through the first half of 2026 by exploiting vulnerabilities in an unidentified financial security software to distribute malware after tricking victims into visiting malicious URLs through spear-phishing and watering hole techniques . Interestingly, some of these incidents have also involved the exploitation of the same financial security software vulnerabilities to deploy Gunra ransomware and exfiltrate sensitive organizational information. Some of the watering hole attacks, per ENKI, have also exploited a zero-day vulnerability in AnySign4PC, causing malware to be installed and executed on systems with the certificate signing software installed when accessing the web page containing the exploit code. Some of the payloads distributed as part of the whole campaign include Struggle (aka SIGNBT 3.0) and Brandoor (aka COPPERHEDGE), both of which are known to be used by the Lazarus Group. "These commonalities suggest that although the state-sponsored threat group and the Gunra ransomware group appear to be separate threat actors with different ultimate objectives, they may have shared certain techniques, tools, and infrastructure or collaborated to a limited extent during the attacks," AhnLab said.
Recommended Actions
- Identify whether the affected product, service or software is present in the environment.
- Review the original vendor or research advisory and verify affected versions before making configuration changes.
- Apply vendor-provided security updates or mitigations as soon as operationally practical.
- Review relevant security logs and monitoring alerts for signs of suspicious activity associated with the reported issue.
- Use the CVE identifiers, where available, to validate exposure through vulnerability-management and asset-inventory tools.
Security Details
- Severity: Critical
- Original source: The Hacker News
Why This Matters
Cybersecurity teams should use reports like this as an input to risk-based vulnerability and threat management rather than relying on headline severity alone. Exposure depends on whether the affected technology is deployed, reachable by an attacker and protected by compensating controls. Confirming asset ownership, affected versions and available vendor fixes helps teams prioritize remediation while avoiding unnecessary emergency changes.
Original Report
NetworkFix recommends reviewing the complete original report from The Hacker News for the authoritative technical context, affected versions, indicators and vendor-specific remediation details: Read the original report.