<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Gunra Ransomware Gang Exploits Fortinet Flaws and Bypasses MFA in Global Attacks

Gunra ransomware targets global critical infrastructure using Fortinet exploits. Agencies urge patching and secure practices.
Content Team

Six US and South Korean agencies, including CISA, the FBI, the NSA, and Korea's National Police Agency, issued joint advisory AA26-222A on Monday, August 10, about Gunra, a ransomware gang that emerged in spring 2025 and has been hitting critical infrastructure worldwide. Built on leaked Conti source code, it added a Dark Web affiliate program in early 2026.

The FBI observed Gunra exploiting two Fortinet authentication bypass flaws — CVE-2024-55591 (CVSS 9.8, critical) and CVE-2025-24472 (8.1, high) — to gain initial access. Both affect FortiOS 7.0.0–7.0.16 and FortiProxy 7.0.0–7.0.19 and 7.2.0–7.2.12, and both have been in CISA's KEV catalog since early 2025, with deadlines that expired in January and April that year.

Attackers also hijacked VPN sessions, stole cookies, and modified authentication processing files on the corporate VDI portal server so that one Gunra-designated one-time password value always succeeded, leaving every login looking legitimate to the identity provider. Backups at both the primary data center and the disaster recovery site were deleted before encryption.

The advisory does carry a recovery route for Linux victims. Breakglass Intelligence found that Gunra's Linux build seeds its random number generator with srand(time(NULL)) — the system clock in seconds when encryption began — allowing the key to be reconstructed from the encrypted files' timestamps. Rebooting, overwriting, or wiping the system destroys that option.

Victims span healthcare, finance, manufacturing, transportation, and government, from South Korea and Brazil to Spain, Australia, and North America. Agencies urge upgrading FortiOS to 7.0.17 or later and FortiProxy to 7.0.20 or 7.2.13, maintaining immutable backups in physically separate locations, and network segmentation.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo