HackMyIP
← Back to News
2026-08-11 The Hacker News

Gunra Ransomware Exploits Fortinet Flaws in Attacks on Critical Sectors

RansomwareThreat IntelVulnerability

A joint cybersecurity advisory from U.S. and South Korean agencies has warned that Gunra ransomware is actively targeting critical infrastructure sectors worldwide, including healthcare and public health, financial services, government services, and professional and nonprofit organizations. CISA Acting Executive Assistant Director for Cybersecurity, Chris Butera, stated that the operation reflects an ongoing trend of ransomware groups causing disruption across U.S. and international organizations. Since emerging in April 2025, the group has listed 51 victims on its dedicated data leak site according to Ransomware.Live data, with most hits reported in South Korea, Brazil, Spain, Thailand, and Hong Kong, while the broader geographic spread heavily favors Australia, East Asia, and Europe. Victims who refuse to pay the ransom within five to seven days have their exfiltrated data published as part of a double extortion model combining encryption and public leak pressure.

Gunra operators gain initial access primarily by chaining two security flaws in internet-exposed Fortinet FortiOS and FortiProxy appliances: CVE-2024-55591 and CVE-2025-24472. Security researcher Rakesh Krishnan noted that phishing remains a supporting vector, with the group using a WhatsApp-themed control panel to negotiate with victims. Once inside the perimeter, affiliates abuse Impacket utilities such as psexec.py, smbclient.py, and secretsdump.py for lateral movement and credential harvesting over SMB. The locker, available in both Windows and Linux builds, encrypts files using advanced stream ciphers including Salsa20 and ChaCha20, capable of processing datasets as large as 9 TB in limited timeframes. Defenders managing Fortinet gear should verify exposed management interfaces with a port scanner and audit any accounts potentially exposed to credential dumping.

The Conti-derived operation formally launched a RaaS affiliate program on dark web forums in January 2026, handing recruits a management panel, configurable ransomware builder, cross-platform payloads, and structured affiliate documentation. The FBI has observed Gunra rebranding under aliases such as "Golden Community" while monetizing its platform by recruiting penetration testers and ethical hackers to act as initial access brokers in exchange for a cut of ransom proceeds. Notably, an analysis released by Breakglass Intelligence in March 2026 identified a catastrophic cryptographic weakness in the Linux variant that allows victims to recover encryption keys and restore files without paying the ransom.

Defenders should immediately patch Fortinet FortiOS and FortiProxy appliances against CVE-2024-55591 and CVE-2025-24472, restrict SMB-based lateral movement through network segmentation, and rotate any credentials that may have been harvested via secretsdump. Security teams should validate that employee credentials used for VPN and webmail access have not surfaced in known compromises using an email breach checker, run a privacy checkup to review the broader attack surface, and leverage WHOIS lookups on newly registered infrastructure tied to Gunra staging operations to generate early-warning indicators of compromise.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →