Six US and South Korean agencies, including CISA, the FBI, the NSA, and Korea's National Police Agency, issued joint advisory AA26-222A on Monday, August 10, about Gunra, a ransomware gang that emerged in spring 2025 and has been hitting critical infrastructure worldwide. Built on leaked Conti source code, it added a Dark Web affiliate program in early 2026.
The FBI observed Gunra exploiting two Fortinet authentication bypass flaws — CVE-2024-55591 (CVSS 9.8, critical) and CVE-2025-24472 (8.1, high) — to gain initial access. Both affect FortiOS 7.0.0–7.0.16 and FortiProxy 7.0.0–7.0.19 and 7.2.0–7.2.12, and both have been in CISA's KEV catalog since early 2025, with deadlines that expired in January and April that year.
Attackers also hijacked VPN sessions, stole cookies, and modified authentication processing files on the corporate VDI portal server so that one Gunra-designated one-time password value always succeeded, leaving every login looking legitimate to the identity provider. Backups at both the primary data center and the disaster recovery site were deleted before encryption.
The advisory does carry a recovery route for Linux victims. Breakglass Intelligence found that Gunra's Linux build seeds its random number generator with srand(time(NULL)) — the system clock in seconds when encryption began — allowing the key to be reconstructed from the encrypted files' timestamps. Rebooting, overwriting, or wiping the system destroys that option.
Victims span healthcare, finance, manufacturing, transportation, and government, from South Korea and Brazil to Spain, Australia, and North America. Agencies urge upgrading FortiOS to 7.0.17 or later and FortiProxy to 7.0.20 or 7.2.13, maintaining immutable backups in physically separate locations, and network segmentation.
Source: Dark Reading