FBI Warns: Gunra Ransomware Exploits Fortinet Flaws to Hit Critical Infrastructure
The FBI and South Korea's National Policy Agency issued a joint cybersecurity advisory on Monday warning that the Gunra ransomware gang, which emerged in April 2025, is actively targeting critical infrastructure organizations worldwide by exploiting vulnerabilities in Fortinet firewall products. Chris Butera, acting executive assistant director for cybersecurity at CISA, confirmed that Gunra is built using source code from the Conti ransomware family, whose inner workings were leaked in 2022. The gang has been leveraging CVE-2024-55591 and CVE-2025-24472—two previously disclosed flaws in Fortinet firewalls—to gain privileged access, exfiltrate sensitive data, and encrypt victim systems before issuing ransom demands.
According to the advisory, Gunra operators have concentrated their attacks on the healthcare, financial services, and government sectors, with ransom demands routinely exceeding $10 million and payment windows of just five to seven days. The FBI noted that Gunra actors have attempted to contact executive staff directly via email to pressure victims into paying, though these efforts have had limited success. Researchers recently observed potential infrastructure and tooling overlaps with North Korea's Lazarus Group, suggesting possible collaboration between the two threat actors. Organizations can verify their external firewall exposure and open ports using a port scanner to identify potential attack surfaces targeted by these initial access brokers. By January, Gunra shifted to a ransomware-as-a-service model and began recruiting affiliates on cybercrime forums, adopting the alias "Golden Community" to expand its operations.
The group initially focused on Windows environments but has since developed a Linux variant, broadening its reach across enterprise infrastructure. Encouragingly, researchers identified a cryptographic weakness in Gunra's Linux encryptor in March that allows defenders to reconstruct decryption keys using file timestamps, enabling victims to recover data without paying. The advisory also tied Gunra's growth to a broader surge in ransomware incidents targeting industrial organizations, with Dragos reporting 1,140 such incidents globally. Security teams are urged to patch the cited Fortinet vulnerabilities immediately, audit credential hygiene with a password checker, and validate encrypted communications using an SSL/TLS checker to harden perimeter defenses against this evolving threat.