Gunra Ransomware Gang Exploits Fortinet Flaws to Bypass MFA
The Gunra ransomware-as-a-service (RaaS) operation has emerged as a significant threat to critical infrastructure organizations, leveraging leaked Conti source code and weaponizing long-known vulnerabilities in Fortinet firewalls and VPN appliances. Active since early 2025, Gunra has rapidly gained traction among affiliates by offering a double-extortion model with robust encryption routines inherited from the dismantled Conti syndicate. Researchers at Trend Micro and the FBI have linked Gunra to multiple intrusions across healthcare, manufacturing, and energy sectors, where the group has successfully exfiltrated sensitive data before deploying payloads that cripple operational technology environments.
Gunra's operators are exploiting unpatched Fortinet devices, including FortiGate firewalls and FortiClient VPN endpoints, by chaining flaws such as CVE-2024-21762—an out-of-bounds write vulnerability in FortiOS SSL VPN—and CVE-2023-48788, an SQL injection in FortiClient EMS, to gain initial access. Once inside a network perimeter, the affiliates pivot using legitimate administrative tools and abuse misconfigured firewall rules to maintain persistence. Organizations can audit their exposure to these risks by running a port scanner to identify open Fortinet management interfaces and a SSL/TLS checker to verify VPN certificate integrity.
A particularly alarming capability in Gunra's playbook is its method for bypassing multi-factor authentication on Fortinet SSO integrations. By harvesting session cookies through Adversary-in-the-Middle (AiTM) proxies deployed on compromised edge devices and replaying them against identity providers, the actors circumvent token-binding protections that organizations rely on. This MFA bypass enables lateral movement into hypervisors, backup servers, and domain controllers, often going undetected for weeks. Security teams should verify credential exposure using an email breach checker and enforce phishing-resistant authentication methods such as FIDO2 hardware keys.
Defenders are urged to immediately patch Fortinet appliances to the latest FortiOS and FortiClient releases, disable unused VPN profiles, and segment OT networks from corporate IT. With Conti's codebase now fueling multiple ransomware families, the threat landscape demands a proactive posture: continuous vulnerability scanning, robust MFA, and 24/7 monitoring of edge device logs are no longer optional for protecting critical infrastructure from Gunra and its successors.