>samit_hota
Back to security news

Security News · SN-2026-366

CRITICALCVE-2024-55591, CVE-2025-24472OPEN

FBI and South Korea Warn of Gunra Ransomware Exploiting Fortinet Firewalls

Affected: Fortinet FortiOS · FortiManager · Critical Infrastructure (Healthcare · Financial Services · Government)

Samit Hota·
#news#ransomware#fbi

Perimeter Firewalls Under Fire from Gunra Ransomware

An aggressive ransomware campaign targeting critical infrastructure organizations worldwide has prompted a joint cybersecurity advisory from the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and South Korea’s National Police Agency. The threat actor behind the attacks, known as the Gunra ransomware gang, is breaching networks by exploiting vulnerabilities in popular Fortinet firewall products—specifically CVE-2024-55591 and CVE-2025-24472. First observed by federal law enforcement in April 2025, Gunra has expanded its operational footprint across the healthcare, financial services, and government sectors globally, leaving impacted organizations facing tight deadlines and steep extortion demands.

“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations,” said Chris Butera, acting executive assistant director for cybersecurity at CISA.

Unauthenticated perimeter exploitation continues to serve as one of the most effective initial access vectors for enterprise intrusions. Firewalls and SSL-VPN appliances sit at the boundary between public internet traffic and sensitive corporate networks. When administrative web portals harbor authentication bypass or remote code execution flaws, they become immediate single points of failure. By leveraging CVE-2024-55591 and CVE-2025-24472, Gunra actors bypass access controls, gain elevated administrative access to edge devices, and pivot directly into core corporate subnets and operational networks. This position grants attackers high-privilege access while bypassing traditional endpoint detection and response (EDR) agents during the crucial initial compromise stage.

Operational Evolution: Conti Lineage and Initial Access Brokers

Gunra is built directly upon source code from the Conti ransomware gang that leaked publicly in 2022. This lineage provides Gunra with fast, multi-threaded file encryption routines designed to rapidly encrypt local storage, target network shares, terminate core database services, and wipe Volume Shadow Copies to prevent local system restoration. While the operation initially targeted Windows environments, the operators subsequently developed a Linux variant designed to encrypt hypervisors and enterprise Linux systems.

The gang’s business model underwent significant commercialization in January when it transitioned to a ransomware-as-a-service (RaaS) platform. To scale operations, Gunra began actively recruiting affiliates on cybercriminal forums and partnering with initial access brokers (IABs). Federal law enforcement observed the group operating under alternative brand names, including “Golden Community,” as it expanded its platform and delegated network breach tasks to specialized initial access vendors.

Industrial cyber security telemetry reflects the group’s persistent activity across manufacturing and infrastructure environments. According to industrial security firm Dragos, global ransomware incidents targeting industrial entities reached 1,140 cases in Q2 2026, marking a 12 percent increase over Q1. Dragos attributed four industrial attacks to Gunra in Q2 2026, following eight confirmed industrial incidents by the group in Q1 2026.

High-Stakes Extortion and North Korean Infrastructure Overlap

Gunra’s extortion strategy involves high-dollar financial demands paired with short payment windows. The FBI observed the gang issuing ransom demands exceeding $10 million, typically giving victim organizations only five to seven days to settle payments before threatening data publication. Rather than relying solely on automated ransom notes left on encrypted servers, Gunra actors frequently attempt direct email communications with executive management and leadership staff at targeted companies to coerce payment.

Security researchers have also uncovered evidence connecting Gunra’s operations to state-sponsored activity. Investigations into incidents targeting South Korean organizations revealed that tools and infrastructure utilized by North Korea’s Lazarus Group appear to have been shared with Gunra, pointing to tactical cooperation or resource sharing between the state-aligned APT and the commercial ransomware operation.

Despite Gunra’s aggressive expansion, defenders recently gained a notable tactical advantage regarding the group’s Linux malware. In March, security researchers identified a cryptographic flaw in Gunra’s Linux variant. The encryption key generation mechanism relies on weak entropy, allowing defenders to reconstruct the encryption keys using file timestamps and successfully recover encrypted files without paying a ransom.

Defensive Recommendations and Remediation

Organizations operating Fortinet perimeter appliances or managing targeted critical infrastructure environments should take immediate action:

  • Apply Fortinet Security Updates: Immediately patch FortiOS and FortiManager instances against CVE-2024-55591 and CVE-2025-24472. Disable public web management interfaces on edge firewalls and restrict administrative access strictly to internal management VLANs or secure jump hosts.
  • Utilize Timestamp Recovery for Linux Ransomware Encounters: If impacted by Gunra’s Linux payload, preserve encrypted volumes and system metadata intact. Responders can mathematically derive the symmetric encryption key using file creation and modification timestamps rather than negotiating with the threat actor.
  • Monitor for Access Broker Activity: Audit network perimeters for unauthorized VPN connections, unusual active administrative sessions on perimeter devices, or credential dumping attempts targeting firewall configuration backups.
  • Prepare Executive Management for Direct Solicitation: Brief executive leadership and incident response teams regarding Gunra’s tactic of sending direct extortion emails to management staff, ensuring these communications are flagged and routed directly to the SOC rather than answered.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call