Gunra Ransomware: Exploiting Fortinet Flaws to Target Critical Infrastructure (2026)

The Rise of Gunra Ransomware: A New Threat to Critical Infrastructure

The world of cybersecurity is abuzz with the emergence of Gunra, a sophisticated ransomware group that has set its sights on critical infrastructure and government organizations. This group has been making waves since its first appearance in 2025, and its evolution is a stark reminder of the ever-changing landscape of cyber threats.

What's particularly concerning is their ability to exploit known vulnerabilities in internet-facing devices, especially firewalls and VPN appliances. These are the digital sentinels guarding our networks, and Gunra has found a way to slip past them unnoticed. This is a classic example of how legacy vulnerabilities, if left unpatched, can become an open invitation for malicious actors.

The Fortinet Connection

The joint advisory from US and Korean authorities highlights two critical Fortinet vulnerabilities that Gunra has been exploiting. These are not new flaws; they are legacy issues that, if unaddressed, can provide a backdoor for attackers. The fact that these vulnerabilities are still effective is a wake-up call for organizations worldwide. It's a reminder that patch management is not just a one-time task but an ongoing process in the battle against cyber threats.

The first vulnerability, CVE-2024-55591, allows remote attackers to gain super-admin privileges, essentially giving them the keys to the kingdom. The second, CVE-2025-24472, is equally concerning, as it enables attackers to bypass authentication protocols and gain control of downstream devices. These are not just theoretical risks; they are actively being exploited, as evidenced by the advisory.

Stealth and Persistence

Gunra's modus operandi is characterized by stealth and persistence. Once inside a network, they employ advanced techniques to move laterally, often going undetected for extended periods. This stealthy approach allows them to exfiltrate vast amounts of data, which is then used as leverage in their double-extortion strategy. They demand ransoms in the tens of millions, a testament to their confidence and the value of the data they steal.

Their ability to bypass authentication protocols is alarming. From exploiting default credentials to modifying authentication processing files, they leave no stone unturned. This is where organizations often fall short. Many focus on patching entry points but overlook the possibility of an authentication backdoor, as Jacob Krell from Suzu Labs astutely points out.

The Human Factor

One fascinating aspect of Gunra's strategy is their timing. They primarily operate during off-hours, when security teams are likely to be less vigilant. This 'out of hours' approach is a clever tactic, exploiting a potential gap in detection capabilities. It's a reminder that cybersecurity is a 24/7 endeavor, and organizations must ensure consistent coverage to counter such threats.

The group's use of extensive filtering rules to target user data is also noteworthy. This level of precision suggests a deep understanding of their targets and a strategic approach to maximize the impact of their attacks.

Defending Against Gunra

The advisory offers valuable insights into countering the Gunra threat. Patching known vulnerabilities is essential, but it's just the beginning. Organizations must also implement robust backup strategies and network segmentation to limit the potential damage.

In my opinion, the key takeaway is the need for a holistic approach to cybersecurity. It's not just about fixing known issues; it's about anticipating potential threats and building a resilient defense. Gunra's evolution from a leaked ransomware source code to a sophisticated RaaS operation underscores the dynamic nature of cyber threats. Staying ahead requires constant vigilance, proactive measures, and a deep understanding of the adversary's tactics.

Gunra Ransomware: Exploiting Fortinet Flaws to Target Critical Infrastructure (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Saturnina Altenwerth DVM

Last Updated:

Views: 6393

Rating: 4.3 / 5 (64 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Saturnina Altenwerth DVM

Birthday: 1992-08-21

Address: Apt. 237 662 Haag Mills, East Verenaport, MO 57071-5493

Phone: +331850833384

Job: District Real-Estate Architect

Hobby: Skateboarding, Taxidermy, Air sports, Painting, Knife making, Letterboxing, Inline skating

Introduction: My name is Saturnina Altenwerth DVM, I am a witty, perfect, combative, beautiful, determined, fancy, determined person who loves writing and wants to share my knowledge and understanding with you.