Gunra Ransomware Is Turning Legacy Fortinet Flaws Into a Gateway to Government and Critical Infrastructure Networks

Listen to this Post

Featured ImageA New Ransomware Warning With an Old Lesson

Ransomware has become far more than a file-encryption problem. Modern criminal operations increasingly begin at the network edge, compromise an identity system, move quietly through an organization, steal enormous quantities of sensitive information, and only then deploy encryption when the attackers are confident they have maximum leverage.

That is precisely why the latest warning surrounding Gunra ransomware deserves serious attention.

U.S. and South Korean authorities have issued a joint advisory warning that Gunra affiliates are exploiting two known Fortinet vulnerabilities to gain privileged access to organizations, including government agencies and critical national infrastructure. The campaign demonstrates a particularly uncomfortable reality for defenders: a vulnerability does not stop being dangerous simply because it is no longer new.

Gunra’s activity is especially concerning because the operation combines vulnerable internet-facing infrastructure, authentication bypasses, stolen credentials, stealthy lateral movement, Microsoft 365 data theft, and double-extortion tactics. Authorities say victims have included organizations across healthcare, financial services, manufacturing, government, transportation, utilities and other critical sectors.

IT Pro

The group has also evolved into a structured ransomware-as-a-service operation, meaning the people gaining initial access do not necessarily have to be the same criminals developing or operating the ransomware itself. This specialization allows attacks to scale much faster.

Gunra’s Evolution From Leaked Conti Code to Ransomware Business

Gunra first appeared in 2025, with researchers linking its ransomware to the Conti source code leak from 2022.

That connection is important because leaked ransomware source code can become the foundation for entirely new criminal operations. Instead of developing every component from scratch, threat actors can reuse proven encryption routines, infrastructure concepts and operational techniques.

By early 2026, Gunra had reportedly moved toward a structured Ransomware-as-a-Service (RaaS) model advertised on underground forums.

The operation also began using additional branding, including the name “Golden Community.”

This transformation matters because RaaS turns ransomware into something resembling a criminal software ecosystem. Affiliates can specialize in obtaining access, while other operators provide ransomware builders, infrastructure and extortion services.

Recent reporting also indicates that

IT Pro

The Two Fortinet Vulnerabilities at the Center of the Warning

Authorities have identified two Fortinet vulnerabilities being exploited by Gunra operators:

CVE-2024-55591 is a critical authentication-bypass vulnerability affecting certain FortiOS and FortiProxy versions. Attackers can abuse specially crafted requests involving the Node.js WebSocket module to obtain highly privileged access.

CVE-2025-24472 is a high-severity authentication-bypass flaw involving

The important point is not simply that both vulnerabilities exist.

The important point is that attackers are using them as practical entry points into real organizations.

Patches are available, but organizations that applied them months ago should not automatically assume that the environment is clean.

Patching the Vulnerability Is Not the Same as Removing the Attacker

This may be the most important lesson in the entire Gunra advisory.

When a firewall or VPN appliance is exploited, the attacker may establish persistence before defenders install a security update.

Applying the patch can close the original vulnerability.

It does not necessarily remove unauthorized accounts, altered authentication mechanisms, stolen credentials, tunnels, scheduled tasks, malware, web shells or other persistence mechanisms that may already exist.

That distinction is critical for incident response.

If a Fortinet device was exposed to the internet while vulnerable, security teams should treat historical exposure as a potential compromise scenario rather than simply asking whether the device is currently patched.

Gunra Has Demonstrated That Authentication Is a Battlefield

The advisory describes an especially worrying example involving an SSL-VPN appliance.

Gunra operators obtained access to an administrator account by abusing default credentials where account lockout protections were not enabled.

This illustrates why authentication security cannot be reduced to simply “we have MFA.”

Organizations need to examine the entire authentication chain.

Default credentials, weak administrative accounts, legacy protocols, excessive privileges, poorly configured lockout policies, stolen sessions and modified authentication components can all undermine an otherwise sophisticated identity-security program.

The MFA Bypass Is More Dangerous Than a Simple Password Theft

One observed Gunra technique involved modifying authentication-processing files on a corporate VDI authentication portal.

The purpose was to enable persistent MFA bypass.

That is considerably more serious than stealing a password.

If an attacker modifies the system responsible for processing authentication, they can potentially manipulate the trust mechanism itself.

In that situation, repeatedly changing user passwords may accomplish very little.

The organization has to establish whether the authentication infrastructure itself remains trustworthy.

This is why post-compromise investigation must extend beyond endpoints and include VPN appliances, identity providers, VDI infrastructure, authentication servers and privileged access systems.

OpenSSH Becomes a Tunnel Into the

Gunra operators have also been observed downloading OpenSSH to establish connections between compromised systems and attacker-controlled infrastructure.

This is an example of a broader trend in modern intrusion operations: attackers increasingly rely on legitimate administrative software rather than obvious malware.

OpenSSH is not inherently malicious.

That is precisely why it can be useful to attackers.

Security teams may see an apparently legitimate administrative utility while overlooking the context in which it was installed, the account executing it, the destination it connects to and the unusual timing of its activity.

This is commonly described as living off the land.

The Attackers Prefer the Hours When Defenders Are Sleeping

Gunra’s operational timing is another fascinating component of the campaign.

Authorities observed malicious activity and internal reconnaissance predominantly between approximately 10 p.m. and 6 a.m. in the victim’s local time zone.

That is not necessarily accidental.

Many organizations have substantially fewer security personnel actively monitoring systems overnight. Even when automated security controls remain operational, human response capability can be reduced.

An attacker who understands the

The lesson is simple:

A SOC that effectively disappears overnight creates a predictable window of opportunity.

Gunra Deletes Evidence While Moving Through the Network

Stealth is central to the operation.

Gunra actors have been observed deleting system and network access logs and clearing command histories.

These techniques are designed to make forensic reconstruction more difficult.

If attackers can compromise an administrator account, move laterally, delete evidence and operate during low-visibility hours, defenders may not discover the intrusion until the ransomware deployment begins.

That is why centralized, tamper-resistant logging is becoming increasingly important.

Logs stored only on the compromised machine are not reliable evidence if the attacker has administrative control over that machine.

Microsoft 365 Is Part of the Ransomware Battlefield

One of the most alarming aspects of the Gunra campaign is its focus on data stored in Microsoft OneDrive and SharePoint.

Ransomware operators increasingly understand that the most valuable asset inside many organizations is not necessarily the file server.

It is the data.

Business documents, financial records, customer information, internal communications, intellectual property and sensitive operational material can all become extortion tools.

The FBI has observed Gunra using malicious executables to steal data from OneDrive and SharePoint.

In at least one incident, attackers reportedly exfiltrated tens of terabytes of information by creating compressed archives and transferring them to the Mega file-sharing platform.

That scale changes the economics of the attack.

Why Double Extortion Makes Gunra So Dangerous

Traditional ransomware attacks attempted to force victims to pay for decryption.

Modern ransomware has evolved.

Gunra combines encryption with data theft.

The victim therefore faces two threats:

Their systems are encrypted.

Their stolen data may be published or otherwise exposed.

This is known as double extortion.

Even an organization with excellent backups can still face enormous pressure if attackers possess sensitive information.

A successful backup strategy can defeat the encryption component.

It cannot automatically undo the consequences of a massive data breach.

Gunra Does Not Need to Encrypt Everything

The ransomware binary reportedly includes filtering mechanisms designed to identify files that are likely to contain meaningful user data.

That approach makes operational sense for an attacker.

Encrypting every possible file consumes time and computing resources.

If the objective is maximum disruption, selectively targeting valuable user data can be more efficient.

It also demonstrates how ransomware has evolved from crude bulk encryption into increasingly deliberate attack tooling.

Tens of Millions of Dollars Are Being Demanded

Gunra ransom notes reportedly begin negotiations with demands reaching into the tens of millions of dollars.

Authorities have described these opening demands as exceptionally high or “arbitrarily high.”

Victims are generally given around five to seven days to initiate negotiations through a Tor-based portal.

In some cases, attackers have reportedly attempted to contact company management directly through email.

This is another indication that modern ransomware operations are not simply technical attacks.

They are carefully engineered pressure campaigns.

The CEO and Boardroom Are Now Part of the Attack Surface

Once criminals begin contacting executives directly, incident response becomes a business crisis.

Executives may suddenly receive threats claiming that confidential information will be published.

Employees may be unable to access critical systems.

Customers may start asking questions.

Regulators may require notification.

Partners may demand explanations.

And meanwhile, technical teams are trying to determine whether the attackers are still inside the environment.

This is why ransomware preparation must include executive-level crisis exercises rather than focusing exclusively on IT procedures.

Critical Infrastructure Is an Especially Attractive Target

Gunra’s reported victims span multiple industries, including healthcare, finance, manufacturing and government.

These sectors share a common characteristic:

downtime is expensive.

A manufacturing company can lose production.

A hospital can experience operational disruption.

A financial organization can face regulatory and reputational consequences.

A government agency may lose access to essential services.

Critical infrastructure therefore represents an attractive target for extortion because attackers understand that the cost of disruption can dramatically exceed the ransom itself.

Why Legacy Vulnerabilities Continue to Win

The Gunra campaign reinforces an uncomfortable cybersecurity truth: attackers do not need zero-days when organizations remain exposed to known vulnerabilities.

Security teams often concentrate heavily on newly disclosed vulnerabilities.

But an old vulnerability on an internet-facing firewall can be much more useful to an attacker than a brand-new vulnerability affecting a system that is not exposed.

The real question is not:

“How old is the vulnerability?”

The real question is:

“Is the vulnerable system still reachable, exploitable and valuable?”

Deep Analysis: Hunting for Gunra-Style Activity

Defenders should begin by identifying every internet-facing Fortinet appliance and determining whether vulnerable versions were previously exposed.

A basic inventory can start with:

nmap -sV -Pn <FORTIGATE_IP>

For authorized internal asset discovery, administrators can also use:

nmap -sV --open -p 443,8443,10443 <NETWORK_RANGE>

These commands should only be used against infrastructure you own or are explicitly authorized to test.

Deep Analysis: Search for Suspicious SSH Activity

Because attackers may deploy OpenSSH for tunneling and persistence, defenders should investigate unusual SSH processes and connections.

On Linux systems:

ps aux | grep -i ssh

Review active network connections:

ss -tulpn

And inspect recent authentication events:

last

On larger environments, the same investigation should be performed through centralized EDR, SIEM and network telemetry rather than manually on individual machines.

Deep Analysis: Look for Unexpected Tunnels

SSH tunnels can hide attacker communications inside legitimate encrypted traffic.

Investigate unusual processes using:

ps aux | grep -E 'ssh|autossh'

Then examine established connections:

ss -tpn

Security teams should pay particular attention to outbound connections from servers that normally have no reason to initiate SSH sessions toward the internet.

Deep Analysis: Investigate Authentication Manipulation

If an organization suspects compromise of its VDI or authentication infrastructure, password resets alone should not be considered sufficient.

Teams should compare authentication components against known-good baselines.

Look for:

find /etc -type f -mtime -14 2>/dev/null

On Windows infrastructure, administrators should instead use approved endpoint and SIEM tooling to identify recently modified authentication-related files, unusual services, new scheduled tasks and unexpected administrative activity.

The objective is not simply to find malware.

The objective is to determine what the attacker changed.

Deep Analysis: Protect Your Logs From the Attacker

If Gunra deletes local logs, centralized collection becomes essential.

Organizations should forward security events to infrastructure that ordinary administrators on compromised endpoints cannot modify or erase.

For Linux environments, useful sources include:

journalctl --since "24 hours ago"

and:

grep -iE 'authentication|sudo|ssh|failed|accepted' /var/log/auth.log

For Windows environments, investigate Security Event Logs, PowerShell activity, authentication events, endpoint telemetry and identity-provider logs through a centralized platform.

Deep Analysis: Hunt for Large-Scale Cloud Data Movement

The OneDrive and SharePoint element deserves special attention.

Security teams should investigate:

Unusual bulk downloads

Abnormal SharePoint access

New OAuth applications

Suspicious service principals

Unusual administrator activity

Large archive creation

Unexpected external sharing

Authentication from unfamiliar locations

Unusual Mega or other file-sharing activity

Mass access to previously untouched repositories

A ransomware investigation that looks only at endpoint encryption may miss the most damaging part of the incident.

Deep Analysis: Examine Identity Before Declaring Victory

If a Fortinet device or authentication system was compromised, defenders should investigate identity infrastructure as a separate incident.

That means reviewing:

Privileged accounts

Newly created users

Password resets

MFA changes

Authentication policies

VPN sessions

OAuth applications

API tokens

Service accounts

VDI administrator accounts

Privileged group membership

Active sessions

The attacker may have left the vulnerable appliance behind while retaining access through stolen or modified identities.

Deep Analysis: Segment the Network Before the Next Incident

Network segmentation is one of the strongest defenses against lateral movement.

Critical systems should not exist on the same unrestricted network segment as ordinary workstations.

Separate, where appropriate:

Internet

|

Edge Firewall / VPN

|

DMZ

|

Identity / Authentication

|

User Network

|

Server Network

|

Critical Infrastructure

|

Backup Environment

The goal is to make every movement step harder.

Compromise of one system should not automatically become compromise of the entire organization.

Deep Analysis: Protect Backups From Ransomware

Backups should be isolated from production credentials and network paths wherever possible.

A useful principle is:

If ransomware can encrypt your backup using the same administrative credentials used to control production, your backup may not actually be a backup.

Organizations should maintain offline or immutable copies and regularly test restoration.

A backup that has never been restored successfully is an assumption, not a recovery strategy.

Deep Analysis: Treat Internet-Facing Devices as High-Value Assets

Firewalls, VPN gateways and remote-access appliances are frequently positioned at the edge of the network.

That makes them exceptionally valuable to attackers.

They should receive:

Accelerated patching

Continuous vulnerability monitoring

Strong administrative authentication

Restricted management access

Configuration integrity monitoring

Centralized logging

Frequent account reviews

Incident-response playbooks

Historical exposure analysis

A firewall is not merely a security control.

If compromised, it can become an attacker-controlled doorway into the organization.

What Undercode Say:

  1. The Most Dangerous Vulnerability May Be the One Everyone Thinks Is Already Fixed

Gunra demonstrates why vulnerability management cannot end when the patch is installed.

  1. Patch Management and Incident Response Must Work Together

A patched device can still contain evidence of an earlier compromise.

3. Internet-Facing Infrastructure Deserves Priority

VPNs and firewalls can provide attackers with an unusually direct path into privileged environments.

  1. Authentication Has Become a Primary Ransomware Target

Gunra’s activity shows that attackers are interested in authentication systems, not merely passwords.

5. MFA Is Powerful but Not Magical

If attackers compromise the authentication-processing infrastructure itself, MFA can potentially be undermined.

6. Default Credentials Remain Embarrassingly Effective

Sophisticated ransomware groups will happily use simple weaknesses when organizations leave them available.

  1. Logging Must Be Designed for Hostile Administrators

Local logs are not enough when an attacker obtains administrative privileges.

8. Centralized Logging Changes the Forensic Equation

Remote telemetry can preserve evidence even when compromised systems are wiped.

  1. The Cloud Is Now a Ransomware Target

OneDrive and SharePoint contain enormous quantities of business-critical information.

  1. Data Theft Can Be More Valuable Than Encryption

Attackers may obtain leverage even when defenders can restore systems from backups.

  1. Tens of Terabytes Changes the Incident-Response Timeline

Large-scale exfiltration can happen before encryption begins.

12. Compression Is a Major Warning Sign

Unexpected creation of enormous archives should receive security attention.

13. File-Sharing Services Can Become Exfiltration Infrastructure

Legitimate cloud and file-sharing services can be abused as transfer channels.

14. Nighttime Monitoring Matters

Gunra’s reported operating hours demonstrate how attackers can exploit predictable staffing patterns.

15. Automated Detection Cannot Be Optional

A security team cannot depend entirely on analysts manually watching systems 24 hours a day.

  1. Identity Telemetry Deserves the Same Attention as Endpoint Telemetry

Authentication events can reveal an intrusion even when malware is difficult to detect.

17. Ransomware Has Become an Access-Broker Economy

RaaS allows criminals to specialize and scale operations.

18. Leaked Source Code Has Long-Term Consequences

The Conti leak continues to influence ransomware development years later.

  1. Criminal Branding Changes Faster Than Defensive Documentation

Security teams must track behavior and infrastructure, not just group names.

  1. “Golden Community” Is a Reminder to Follow Techniques

Aliases can change while tactics remain recognizable.

21. Critical Infrastructure Has a Structural Disadvantage

Many critical organizations cannot simply shut everything down when an incident occurs.

22. Attackers Understand Business Pressure

The ransom negotiation process is designed to exploit operational urgency.

  1. Executive Communication Is Part of Incident Response

Direct emails to management show how technical attacks can rapidly become board-level crises.

24. Backups Remain Essential

Even though backups cannot prevent data theft, they can dramatically reduce the leverage provided by encryption.

25. Immutable Backups Are Particularly Important

If attackers can modify backups, recovery becomes significantly more difficult.

26. Segmentation Limits the Blast Radius

The first compromised device should never automatically provide access to everything else.

27. Privileged Access Should Be Minimized

Super-admin access to edge devices can provide enormous attacker leverage.

28. Configuration Changes Need Monitoring

Unexpected modifications to authentication systems should trigger investigation.

29. Vulnerability Scanning Should Include Historical Exposure

Organizations need to know not only what is vulnerable today but what was exposed yesterday.

30. Patch Verification Matters

A patch should be followed by validation that the vulnerable version is actually gone.

  1. Credential Rotation Should Follow Suspected Edge-Device Compromise

Attackers may have already captured credentials before remediation.

32. MFA Reset Alone Is Not Enough

Sessions, tokens, policies and authentication infrastructure may also require investigation.

33. Ransomware Detection Must Include Data Theft

Encryption detection alone is no longer sufficient.

  1. Cloud Audit Logs Can Become Critical Evidence

Microsoft 365 activity may reveal the earliest signs of bulk collection.

35. Outbound Traffic Deserves More Attention

Defenders frequently focus on inbound exploitation while overlooking massive outbound transfers.

36. Attackers Are Becoming Operationally Efficient

Gunra’s filtering and scheduling techniques demonstrate an increasingly disciplined criminal operation.

37. “Known Exploited” Should Mean “Emergency”

When exploitation is confirmed, ordinary patching schedules may be too slow.

38. Cyber Resilience Is More Than Prevention

Organizations must assume that some defensive layers will eventually fail.

39. The Best Defense Is Layered

Patch management, identity security, segmentation, logging, backups and threat hunting must reinforce one another.

  1. Gunra Is a Warning About the Entire Attack Chain

The real danger is not one Fortinet vulnerability. It is the combination of edge compromise, privilege escalation, persistence, lateral movement, cloud data theft and extortion.

✅ Gunra Is Exploiting Fortinet Vulnerabilities

Confirmed: U.S. and South Korean authorities have warned that Gunra has been exploiting known Fortinet vulnerabilities, including CVE-2024-55591 and CVE-2025-24472.

IT Pro

✅ Gunra Operates as Ransomware-as-a-Service

Confirmed: Reporting on the advisory describes Gunra as an RaaS operation that expanded through affiliates and underground recruitment.

IT Pro

✅ The Group Uses Double Extortion

Confirmed: Gunra combines data theft with encryption and threatens victims with publication of stolen information if ransom demands are not met.

IT Pro

✅ Government and Critical Sectors Are Among the Targets

Confirmed: Reported victims span government and multiple critical industries, including healthcare, finance, manufacturing, transportation and utilities.

IT Pro

✅ Tens of Terabytes of Data Can Be Stolen

The supplied advisory reports an incident involving exfiltration on the scale of tens of terabytes, demonstrating that Gunra’s operation is not limited to small collections of documents.

⚠️ Patching Does Not Automatically Prove a System Is Clean

This is an important defensive interpretation rather than a claim that every patched Fortinet device remains compromised. If exploitation occurred before patching, organizations still need to investigate persistence, credentials and authentication infrastructure.

Prediction

(+1) Ransomware Groups Will Continue Targeting Network-Edge Appliances

The economics strongly favor this strategy. Firewalls, VPN gateways and remote-access systems sit at strategically valuable points in corporate networks, and compromising them can provide attackers with privileged access without requiring an employee to open a malicious attachment.

(+1) Authentication Infrastructure Will Become an Even Bigger Ransomware Target

Gunra’s reported MFA-bypass activity highlights where ransomware operations are heading. Instead of merely stealing credentials, attackers will increasingly attempt to manipulate the systems responsible for deciding whether credentials should be trusted.

(+1) Microsoft 365 Data Theft Will Become Central to Extortion

As organizations migrate more business information into OneDrive, SharePoint and other cloud platforms, attackers have increasing incentives to steal cloud data before deploying ransomware.

(+1) Ransomware Operations Will Become More Specialized

The RaaS model allows initial-access brokers, exploit developers, ransomware operators, negotiators and data-theft specialists to work as separate components of the same criminal economy.

(-1) Organizations That Treat Patching as the Entire Remediation Process Will Remain Vulnerable

The biggest mistake defenders can make after an edge-device exploit is assuming that installing the vendor patch automatically removes everything the attacker may have established afterward.

(+1) Nighttime Detection Will Become a Bigger Security Priority

Attackers understand staffing patterns. Organizations with strong daytime security but weak overnight visibility will increasingly become attractive targets.

(+1) The Winning Defense Will Be Cyber Resilience, Not a Single Security Product

Gunra’s campaign demonstrates that no single control is sufficient. The organizations best positioned to survive this type of attack will combine rapid vulnerability remediation, phishing-resistant authentication, privileged-access controls, centralized logging, network segmentation, cloud monitoring, threat hunting and immutable recovery systems.

The Bigger Lesson: Gunra Is Not Really About Two Fortinet CVEs

The headline may be about CVE-2024-55591 and CVE-2025-24472, but the larger story is much more important.

Gunra is demonstrating how a modern ransomware operation can turn one vulnerable internet-facing appliance into a complete intrusion campaign.

The attacker enters through the edge.

Privileges are obtained.

Authentication is manipulated.

Persistence is established.

Credentials are stolen.

The network is mapped.

Defensive logs are weakened.

Cloud data is collected.

Massive archives are created.

Sensitive information leaves the organization.

Only after the attackers have built sufficient leverage does ransomware become the final weapon.

That is the modern ransomware model.

And it means defenders should stop asking only “Have we patched the vulnerability?”

The better question is:

“If this vulnerability was exploited yesterday, can we prove what happened afterward?”

That question is much harder.

It is also the question that can determine whether a ransomware incident remains a contained security event—or becomes a multimillion-dollar organizational crisis.

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://www.discord.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube