Listen to this Post
A New Ransomware Warning With an Old Lesson
Ransomware has become far more than a file-encryption problem. Modern criminal operations increasingly begin at the network edge, compromise an identity system, move quietly through an organization, steal enormous quantities of sensitive information, and only then deploy encryption when the attackers are confident they have maximum leverage.
That is precisely why the latest warning surrounding Gunra ransomware deserves serious attention.
U.S. and South Korean authorities have issued a joint advisory warning that Gunra affiliates are exploiting two known Fortinet vulnerabilities to gain privileged access to organizations, including government agencies and critical national infrastructure. The campaign demonstrates a particularly uncomfortable reality for defenders: a vulnerability does not stop being dangerous simply because it is no longer new.
Gunra’s activity is especially concerning because the operation combines vulnerable internet-facing infrastructure, authentication bypasses, stolen credentials, stealthy lateral movement, Microsoft 365 data theft, and double-extortion tactics. Authorities say victims have included organizations across healthcare, financial services, manufacturing, government, transportation, utilities and other critical sectors.
IT Pro
The group has also evolved into a structured ransomware-as-a-service operation, meaning the people gaining initial access do not necessarily have to be the same criminals developing or operating the ransomware itself. This specialization allows attacks to scale much faster.
Gunra’s Evolution From Leaked Conti Code to Ransomware Business
Gunra first appeared in 2025, with researchers linking its ransomware to the Conti source code leak from 2022.
That connection is important because leaked ransomware source code can become the foundation for entirely new criminal operations. Instead of developing every component from scratch, threat actors can reuse proven encryption routines, infrastructure concepts and operational techniques.
By early 2026, Gunra had reportedly moved toward a structured Ransomware-as-a-Service (RaaS) model advertised on underground forums.
The operation also began using additional branding, including the name “Golden Community.”
This transformation matters because RaaS turns ransomware into something resembling a criminal software ecosystem. Affiliates can specialize in obtaining access, while other operators provide ransomware builders, infrastructure and extortion services.
Recent reporting also indicates that
IT Pro
The Two Fortinet Vulnerabilities at the Center of the Warning
Authorities have identified two Fortinet vulnerabilities being exploited by Gunra operators:
CVE-2024-55591 is a critical authentication-bypass vulnerability affecting certain FortiOS and FortiProxy versions. Attackers can abuse specially crafted requests involving the Node.js WebSocket module to obtain highly privileged access.
CVE-2025-24472 is a high-severity authentication-bypass flaw involving
The important point is not simply that both vulnerabilities exist.
The important point is that attackers are using them as practical entry points into real organizations.
Patches are available, but organizations that applied them months ago should not automatically assume that the environment is clean.
Patching the Vulnerability Is Not the Same as Removing the Attacker
This may be the most important lesson in the entire Gunra advisory.
When a firewall or VPN appliance is exploited, the attacker may establish persistence before defenders install a security update.
Applying the patch can close the original vulnerability.
It does not necessarily remove unauthorized accounts, altered authentication mechanisms, stolen credentials, tunnels, scheduled tasks, malware, web shells or other persistence mechanisms that may already exist.
That distinction is critical for incident response.
If a Fortinet device was exposed to the internet while vulnerable, security teams should treat historical exposure as a potential compromise scenario rather than simply asking whether the device is currently patched.
Gunra Has Demonstrated That Authentication Is a Battlefield
The advisory describes an especially worrying example involving an SSL-VPN appliance.
Gunra operators obtained access to an administrator account by abusing default credentials where account lockout protections were not enabled.
This illustrates why authentication security cannot be reduced to simply “we have MFA.”
Organizations need to examine the entire authentication chain.
Default credentials, weak administrative accounts, legacy protocols, excessive privileges, poorly configured lockout policies, stolen sessions and modified authentication components can all undermine an otherwise sophisticated identity-security program.
The MFA Bypass Is More Dangerous Than a Simple Password Theft
One observed Gunra technique involved modifying authentication-processing files on a corporate VDI authentication portal.
The purpose was to enable persistent MFA bypass.
That is considerably more serious than stealing a password.
If an attacker modifies the system responsible for processing authentication, they can potentially manipulate the trust mechanism itself.
In that situation, repeatedly changing user passwords may accomplish very little.
The organization has to establish whether the authentication infrastructure itself remains trustworthy.
This is why post-compromise investigation must extend beyond endpoints and include VPN appliances, identity providers, VDI infrastructure, authentication servers and privileged access systems.
OpenSSH Becomes a Tunnel Into the
Gunra operators have also been observed downloading OpenSSH to establish connections between compromised systems and attacker-controlled infrastructure.
This is an example of a broader trend in modern intrusion operations: attackers increasingly rely on legitimate administrative software rather than obvious malware.
OpenSSH is not inherently malicious.
That is precisely why it can be useful to attackers.
Security teams may see an apparently legitimate administrative utility while overlooking the context in which it was installed, the account executing it, the destination it connects to and the unusual timing of its activity.
This is commonly described as living off the land.
The Attackers Prefer the Hours When Defenders Are Sleeping
Gunra’s operational timing is another fascinating component of the campaign.
Authorities observed malicious activity and internal reconnaissance predominantly between approximately 10 p.m. and 6 a.m. in the victim’s local time zone.
That is not necessarily accidental.
Many organizations have substantially fewer security personnel actively monitoring systems overnight. Even when automated security controls remain operational, human response capability can be reduced.
An attacker who understands the
The lesson is simple:
A SOC that effectively disappears overnight creates a predictable window of opportunity.
Gunra Deletes Evidence While Moving Through the Network
Stealth is central to the operation.
Gunra actors have been observed deleting system and network access logs and clearing command histories.
These techniques are designed to make forensic reconstruction more difficult.
If attackers can compromise an administrator account, move laterally, delete evidence and operate during low-visibility hours, defenders may not discover the intrusion until the ransomware deployment begins.
That is why centralized, tamper-resistant logging is becoming increasingly important.
Logs stored only on the compromised machine are not reliable evidence if the attacker has administrative control over that machine.
Microsoft 365 Is Part of the Ransomware Battlefield
One of the most alarming aspects of the Gunra campaign is its focus on data stored in Microsoft OneDrive and SharePoint.
Ransomware operators increasingly understand that the most valuable asset inside many organizations is not necessarily the file server.
It is the data.
Business documents, financial records, customer information, internal communications, intellectual property and sensitive operational material can all become extortion tools.
The FBI has observed Gunra using malicious executables to steal data from OneDrive and SharePoint.
In at least one incident, attackers reportedly exfiltrated tens of terabytes of information by creating compressed archives and transferring them to the Mega file-sharing platform.
That scale changes the economics of the attack.
Why Double Extortion Makes Gunra So Dangerous
Traditional ransomware attacks attempted to force victims to pay for decryption.
Modern ransomware has evolved.
Gunra combines encryption with data theft.
The victim therefore faces two threats:
Their systems are encrypted.
Their stolen data may be published or otherwise exposed.
This is known as double extortion.
Even an organization with excellent backups can still face enormous pressure if attackers possess sensitive information.
A successful backup strategy can defeat the encryption component.
It cannot automatically undo the consequences of a massive data breach.
Gunra Does Not Need to Encrypt Everything
The ransomware binary reportedly includes filtering mechanisms designed to identify files that are likely to contain meaningful user data.
That approach makes operational sense for an attacker.
Encrypting every possible file consumes time and computing resources.
If the objective is maximum disruption, selectively targeting valuable user data can be more efficient.
It also demonstrates how ransomware has evolved from crude bulk encryption into increasingly deliberate attack tooling.
Tens of Millions of Dollars Are Being Demanded
Gunra ransom notes reportedly begin negotiations with demands reaching into the tens of millions of dollars.
Authorities have described these opening demands as exceptionally high or “arbitrarily high.”
Victims are generally given around five to seven days to initiate negotiations through a Tor-based portal.
In some cases, attackers have reportedly attempted to contact company management directly through email.
This is another indication that modern ransomware operations are not simply technical attacks.
They are carefully engineered pressure campaigns.
The CEO and Boardroom Are Now Part of the Attack Surface
Once criminals begin contacting executives directly, incident response becomes a business crisis.
Executives may suddenly receive threats claiming that confidential information will be published.
Employees may be unable to access critical systems.
Customers may start asking questions.
Regulators may require notification.
Partners may demand explanations.
And meanwhile, technical teams are trying to determine whether the attackers are still inside the environment.
This is why ransomware preparation must include executive-level crisis exercises rather than focusing exclusively on IT procedures.
Critical Infrastructure Is an Especially Attractive Target
Gunra’s reported victims span multiple industries, including healthcare, finance, manufacturing and government.
These sectors share a common characteristic:
downtime is expensive.
A manufacturing company can lose production.
A hospital can experience operational disruption.
A financial organization can face regulatory and reputational consequences.
A government agency may lose access to essential services.
Critical infrastructure therefore represents an attractive target for extortion because attackers understand that the cost of disruption can dramatically exceed the ransom itself.
Why Legacy Vulnerabilities Continue to Win
The Gunra campaign reinforces an uncomfortable cybersecurity truth: attackers do not need zero-days when organizations remain exposed to known vulnerabilities.
Security teams often concentrate heavily on newly disclosed vulnerabilities.
But an old vulnerability on an internet-facing firewall can be much more useful to an attacker than a brand-new vulnerability affecting a system that is not exposed.
The real question is not:
“How old is the vulnerability?”
The real question is:
“Is the vulnerable system still reachable, exploitable and valuable?”
Deep Analysis: Hunting for Gunra-Style Activity
Defenders should begin by identifying every internet-facing Fortinet appliance and determining whether vulnerable versions were previously exposed.
A basic inventory can start with:
nmap -sV -Pn <FORTIGATE_IP>
For authorized internal asset discovery, administrators can also use:
nmap -sV --open -p 443,8443,10443 <NETWORK_RANGE>
These commands should only be used against infrastructure you own or are explicitly authorized to test.
Deep Analysis: Search for Suspicious SSH Activity
Because attackers may deploy OpenSSH for tunneling and persistence, defenders should investigate unusual SSH processes and connections.
On Linux systems:
ps aux | grep -i ssh
Review active network connections:
ss -tulpn
And inspect recent authentication events:
last
On larger environments, the same investigation should be performed through centralized EDR, SIEM and network telemetry rather than manually on individual machines.
Deep Analysis: Look for Unexpected Tunnels
SSH tunnels can hide attacker communications inside legitimate encrypted traffic.
Investigate unusual processes using:
ps aux | grep -E 'ssh|autossh'
Then examine established connections:
ss -tpn
Security teams should pay particular attention to outbound connections from servers that normally have no reason to initiate SSH sessions toward the internet.
Deep Analysis: Investigate Authentication Manipulation
If an organization suspects compromise of its VDI or authentication infrastructure, password resets alone should not be considered sufficient.
Teams should compare authentication components against known-good baselines.
Look for:
find /etc -type f -mtime -14 2>/dev/null
On Windows infrastructure, administrators should instead use approved endpoint and SIEM tooling to identify recently modified authentication-related files, unusual services, new scheduled tasks and unexpected administrative activity.
The objective is not simply to find malware.
The objective is to determine what the attacker changed.
Deep Analysis: Protect Your Logs From the Attacker
If Gunra deletes local logs, centralized collection becomes essential.
Organizations should forward security events to infrastructure that ordinary administrators on compromised endpoints cannot modify or erase.
For Linux environments, useful sources include:
journalctl --since "24 hours ago"
and:
grep -iE 'authentication|sudo|ssh|failed|accepted' /var/log/auth.log
For Windows environments, investigate Security Event Logs, PowerShell activity, authentication events, endpoint telemetry and identity-provider logs through a centralized platform.
Deep Analysis: Hunt for Large-Scale Cloud Data Movement
The OneDrive and SharePoint element deserves special attention.
Security teams should investigate:
Unusual bulk downloads
Abnormal SharePoint access
New OAuth applications
Suspicious service principals
Unusual administrator activity
Large archive creation
Unexpected external sharing
Authentication from unfamiliar locations
Unusual Mega or other file-sharing activity
Mass access to previously untouched repositories
A ransomware investigation that looks only at endpoint encryption may miss the most damaging part of the incident.
Deep Analysis: Examine Identity Before Declaring Victory
If a Fortinet device or authentication system was compromised, defenders should investigate identity infrastructure as a separate incident.
That means reviewing:
Privileged accounts
Newly created users
Password resets
MFA changes
Authentication policies
VPN sessions
OAuth applications
API tokens
Service accounts
VDI administrator accounts
Privileged group membership
Active sessions
The attacker may have left the vulnerable appliance behind while retaining access through stolen or modified identities.
Deep Analysis: Segment the Network Before the Next Incident
Network segmentation is one of the strongest defenses against lateral movement.
Critical systems should not exist on the same unrestricted network segment as ordinary workstations.
Separate, where appropriate:
Internet
|
Edge Firewall / VPN
|
DMZ
|
Identity / Authentication
|
User Network
|
Server Network
|
Critical Infrastructure
|
Backup Environment
The goal is to make every movement step harder.
Compromise of one system should not automatically become compromise of the entire organization.
Deep Analysis: Protect Backups From Ransomware
Backups should be isolated from production credentials and network paths wherever possible.
A useful principle is:
If ransomware can encrypt your backup using the same administrative credentials used to control production, your backup may not actually be a backup.
Organizations should maintain offline or immutable copies and regularly test restoration.
A backup that has never been restored successfully is an assumption, not a recovery strategy.
Deep Analysis: Treat Internet-Facing Devices as High-Value Assets
Firewalls, VPN gateways and remote-access appliances are frequently positioned at the edge of the network.
That makes them exceptionally valuable to attackers.
They should receive:
Accelerated patching
Continuous vulnerability monitoring
Strong administrative authentication
Restricted management access
Configuration integrity monitoring
Centralized logging
Frequent account reviews
Incident-response playbooks
Historical exposure analysis
A firewall is not merely a security control.
If compromised, it can become an attacker-controlled doorway into the organization.
What Undercode Say:
- The Most Dangerous Vulnerability May Be the One Everyone Thinks Is Already Fixed
Gunra demonstrates why vulnerability management cannot end when the patch is installed.
- Patch Management and Incident Response Must Work Together
A patched device can still contain evidence of an earlier compromise.
3. Internet-Facing Infrastructure Deserves Priority
VPNs and firewalls can provide attackers with an unusually direct path into privileged environments.
- Authentication Has Become a Primary Ransomware Target
Gunra’s activity shows that attackers are interested in authentication systems, not merely passwords.
5. MFA Is Powerful but Not Magical
If attackers compromise the authentication-processing infrastructure itself, MFA can potentially be undermined.
6. Default Credentials Remain Embarrassingly Effective
Sophisticated ransomware groups will happily use simple weaknesses when organizations leave them available.
- Logging Must Be Designed for Hostile Administrators
Local logs are not enough when an attacker obtains administrative privileges.
8. Centralized Logging Changes the Forensic Equation
Remote telemetry can preserve evidence even when compromised systems are wiped.
- The Cloud Is Now a Ransomware Target
OneDrive and SharePoint contain enormous quantities of business-critical information.
- Data Theft Can Be More Valuable Than Encryption
Attackers may obtain leverage even when defenders can restore systems from backups.
- Tens of Terabytes Changes the Incident-Response Timeline
Large-scale exfiltration can happen before encryption begins.
12. Compression Is a Major Warning Sign
Unexpected creation of enormous archives should receive security attention.
13. File-Sharing Services Can Become Exfiltration Infrastructure
Legitimate cloud and file-sharing services can be abused as transfer channels.
14. Nighttime Monitoring Matters
Gunra’s reported operating hours demonstrate how attackers can exploit predictable staffing patterns.
15. Automated Detection Cannot Be Optional
A security team cannot depend entirely on analysts manually watching systems 24 hours a day.
- Identity Telemetry Deserves the Same Attention as Endpoint Telemetry
Authentication events can reveal an intrusion even when malware is difficult to detect.
17. Ransomware Has Become an Access-Broker Economy
RaaS allows criminals to specialize and scale operations.
18. Leaked Source Code Has Long-Term Consequences
The Conti leak continues to influence ransomware development years later.
- Criminal Branding Changes Faster Than Defensive Documentation
Security teams must track behavior and infrastructure, not just group names.
- “Golden Community” Is a Reminder to Follow Techniques
Aliases can change while tactics remain recognizable.
21. Critical Infrastructure Has a Structural Disadvantage
Many critical organizations cannot simply shut everything down when an incident occurs.
22. Attackers Understand Business Pressure
The ransom negotiation process is designed to exploit operational urgency.
- Executive Communication Is Part of Incident Response
Direct emails to management show how technical attacks can rapidly become board-level crises.
24. Backups Remain Essential
Even though backups cannot prevent data theft, they can dramatically reduce the leverage provided by encryption.
25. Immutable Backups Are Particularly Important
If attackers can modify backups, recovery becomes significantly more difficult.
26. Segmentation Limits the Blast Radius
The first compromised device should never automatically provide access to everything else.
27. Privileged Access Should Be Minimized
Super-admin access to edge devices can provide enormous attacker leverage.
28. Configuration Changes Need Monitoring
Unexpected modifications to authentication systems should trigger investigation.
29. Vulnerability Scanning Should Include Historical Exposure
Organizations need to know not only what is vulnerable today but what was exposed yesterday.
30. Patch Verification Matters
A patch should be followed by validation that the vulnerable version is actually gone.
- Credential Rotation Should Follow Suspected Edge-Device Compromise
Attackers may have already captured credentials before remediation.
32. MFA Reset Alone Is Not Enough
Sessions, tokens, policies and authentication infrastructure may also require investigation.
33. Ransomware Detection Must Include Data Theft
Encryption detection alone is no longer sufficient.
- Cloud Audit Logs Can Become Critical Evidence
Microsoft 365 activity may reveal the earliest signs of bulk collection.
35. Outbound Traffic Deserves More Attention
Defenders frequently focus on inbound exploitation while overlooking massive outbound transfers.
36. Attackers Are Becoming Operationally Efficient
Gunra’s filtering and scheduling techniques demonstrate an increasingly disciplined criminal operation.
37. “Known Exploited” Should Mean “Emergency”
When exploitation is confirmed, ordinary patching schedules may be too slow.
38. Cyber Resilience Is More Than Prevention
Organizations must assume that some defensive layers will eventually fail.
39. The Best Defense Is Layered
Patch management, identity security, segmentation, logging, backups and threat hunting must reinforce one another.
- Gunra Is a Warning About the Entire Attack Chain
The real danger is not one Fortinet vulnerability. It is the combination of edge compromise, privilege escalation, persistence, lateral movement, cloud data theft and extortion.
✅ Gunra Is Exploiting Fortinet Vulnerabilities
Confirmed: U.S. and South Korean authorities have warned that Gunra has been exploiting known Fortinet vulnerabilities, including CVE-2024-55591 and CVE-2025-24472.
IT Pro
✅ Gunra Operates as Ransomware-as-a-Service
Confirmed: Reporting on the advisory describes Gunra as an RaaS operation that expanded through affiliates and underground recruitment.
IT Pro
✅ The Group Uses Double Extortion
Confirmed: Gunra combines data theft with encryption and threatens victims with publication of stolen information if ransom demands are not met.
IT Pro
✅ Government and Critical Sectors Are Among the Targets
Confirmed: Reported victims span government and multiple critical industries, including healthcare, finance, manufacturing, transportation and utilities.
IT Pro
✅ Tens of Terabytes of Data Can Be Stolen
The supplied advisory reports an incident involving exfiltration on the scale of tens of terabytes, demonstrating that Gunra’s operation is not limited to small collections of documents.
⚠️ Patching Does Not Automatically Prove a System Is Clean
This is an important defensive interpretation rather than a claim that every patched Fortinet device remains compromised. If exploitation occurred before patching, organizations still need to investigate persistence, credentials and authentication infrastructure.
Prediction
(+1) Ransomware Groups Will Continue Targeting Network-Edge Appliances
The economics strongly favor this strategy. Firewalls, VPN gateways and remote-access systems sit at strategically valuable points in corporate networks, and compromising them can provide attackers with privileged access without requiring an employee to open a malicious attachment.
(+1) Authentication Infrastructure Will Become an Even Bigger Ransomware Target
Gunra’s reported MFA-bypass activity highlights where ransomware operations are heading. Instead of merely stealing credentials, attackers will increasingly attempt to manipulate the systems responsible for deciding whether credentials should be trusted.
(+1) Microsoft 365 Data Theft Will Become Central to Extortion
As organizations migrate more business information into OneDrive, SharePoint and other cloud platforms, attackers have increasing incentives to steal cloud data before deploying ransomware.
(+1) Ransomware Operations Will Become More Specialized
The RaaS model allows initial-access brokers, exploit developers, ransomware operators, negotiators and data-theft specialists to work as separate components of the same criminal economy.
(-1) Organizations That Treat Patching as the Entire Remediation Process Will Remain Vulnerable
The biggest mistake defenders can make after an edge-device exploit is assuming that installing the vendor patch automatically removes everything the attacker may have established afterward.
(+1) Nighttime Detection Will Become a Bigger Security Priority
Attackers understand staffing patterns. Organizations with strong daytime security but weak overnight visibility will increasingly become attractive targets.
(+1) The Winning Defense Will Be Cyber Resilience, Not a Single Security Product
Gunra’s campaign demonstrates that no single control is sufficient. The organizations best positioned to survive this type of attack will combine rapid vulnerability remediation, phishing-resistant authentication, privileged-access controls, centralized logging, network segmentation, cloud monitoring, threat hunting and immutable recovery systems.
The Bigger Lesson: Gunra Is Not Really About Two Fortinet CVEs
The headline may be about CVE-2024-55591 and CVE-2025-24472, but the larger story is much more important.
Gunra is demonstrating how a modern ransomware operation can turn one vulnerable internet-facing appliance into a complete intrusion campaign.
The attacker enters through the edge.
Privileges are obtained.
Authentication is manipulated.
Persistence is established.
Credentials are stolen.
The network is mapped.
Defensive logs are weakened.
Cloud data is collected.
Massive archives are created.
Sensitive information leaves the organization.
Only after the attackers have built sufficient leverage does ransomware become the final weapon.
That is the modern ransomware model.
And it means defenders should stop asking only “Have we patched the vulnerability?”
The better question is:
“If this vulnerability was exploited yesterday, can we prove what happened afterward?”
That question is much harder.
It is also the question that can determine whether a ransomware incident remains a contained security event—or becomes a multimillion-dollar organizational crisis.
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://www.discord.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




