HomeMalware & ThreatsGunra Ransomware Exploits Vulnerabilities in Fortinet FortiOS and FortiProxy to Compromise Networks

Gunra Ransomware Exploits Vulnerabilities in Fortinet FortiOS and FortiProxy to Compromise Networks

Published on

spot_img

Rising Threat: Gunra Ransomware Targets Critical Infrastructure

Cybersecurity and intelligence agencies from South Korea and the United States have raised alarms regarding an emergent ransomware threat known as Gunra. This malware has been identified as targeting critical infrastructure sectors and organizations on a global scale, demonstrating a serious and escalating trend in cybercriminal activities that compromises health systems, financial institutions, government services, and various nonprofit organizations.

Chris Butera, the Acting Executive Assistant Director for Cybersecurity at the Cybersecurity and Infrastructure Security Agency (CISA), emphasized the severity of the situation. He stated that "Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations." The broader implications of these attacks are concerning, as they not only threaten the operational integrity of affected entities but also put sensitive data at risk.

The ransomware’s deployment has involved leveraging security vulnerabilities in widely-used internet-facing appliances such as Fortinet’s FortiOS and FortiProxy. Specific vulnerabilities, identified as CVE-2024-55591 and CVE-2025-24472, provide attackers with initial access to the systems, enabling them to implement the ransomware effectively. This double extortion model, which combines data encryption and data exfiltration, maximizes its impact on the victims. If organizations refuse to pay the ransom within a specified period—usually between five to seven days—the attackers often publish sensitive data on dedicated leak sites, further crippling the victims’ reputations and operations.

Since its emergence in April 2025, Gunra has reportedly affected at least 51 victims, with a significant concentration in South Korea, alongside targets in Brazil, Spain, Thailand, and Hong Kong. The primary focus on victims from regions such as Australia, East Asia, and Europe underscores the ransomware’s strategic targeting. Remarkably, only a handful of attacks have been reported in Canada and the U.S., indicating a potential focus of operations outside North America.

Security analysts, including researcher Rakesh Krishnan, have pointed out that the gang behind Gunra employs phishing as a primary attack vector. This approach aids in delivering malicious payloads to their targets while also facilitating negotiations through a chat interface reminiscent of WhatsApp, adding an unsettling personal touch to the threat of extortion. Moreover, the group has demonstrated advanced capabilities, reportedly able to encrypt vast amounts of data—up to 9 terabytes—within a short period using sophisticated stream cipher encryption algorithms like Salsa20 and ChaCha20.

Further analysis has linked Gunra to a broader criminal network, suggesting connections to the notorious Conti ransomware operation. It appears that the group has launched a Ransomware-as-a-Service (RaaS) affiliate program through dark web forums. This program provides affiliates with a management panel and customizable tools, allowing a wider circle of cybercriminals to perpetrate these attacks, thus expanding the group’s influence.

Interestingly, Gunra has tailored itself to target both Windows and Linux systems, signaling a sophisticated level of operational versatility. Yet, an investigation revealed a significant flaw in the Linux variant, allowing potential access to files without the demand for ransom payment, showcasing the ever-evolving dynamics of ransomware threats.

From a tactical perspective, the FBI has noted that Gunra potentially utilizes various branding aliases, such as Golden Community, to further its operational goals. The group’s monetization strategy includes recruiting penetration testers and ethical hackers, who assist in gaining initial access to targeted networks in exchange for a share of the ransom coffers.

The techniques employed by Gunra also reveal a level of technical sophistication. Attackers have been known to employ lateral movement utilizing Impacket libraries, conducting credential dumping to extract user password hashes and further infiltrate networks. Additionally, during the malicious activities, they have routinely deleted system and access logs to mask their presence, making detection exceedingly difficult for security teams.

Moreover, the attackers have utilized advanced tactics to exfiltrate sensitive organizational data, including cherry-picking critical business documents and connecting to virtual desktop infrastructures (VDI) to gather necessary configurations. The group has even manipulated SSL-VPN appliances to intercept user credentials, making multi-factor authentication less effective by compromising the integrity of the authentication process.

In heightening the risk, a series of watering hole attacks have exploited vulnerabilities in financial security software, allowing ransomware to be installed on compromised systems. This highlights a worrying trend where different threat actors may collaborate or share techniques to bolster their respective campaigns. Notably, past incidents involving North Korean groups indicate a disturbing alliance with ransomware entities, further complicating the landscape of cyber threats.

As Gunra continues to evolve, experts stress the need for organizations to adopt stringent security measures. Recommendations include regular patching of known vulnerabilities, enforcing robust network segmentation, and ensuring the immutability of backups stored in physically separate locations to enhance resilience against potential attacks.

In conclusion, Gunra serves as a stark reminder of the ever-present threats in today’s cyber landscape. The collaboration between state-sponsored operations and ransomware groups introduces a new level of complexity to global cybersecurity challenges. Understanding these dynamics and enhancing defenses accordingly will be vital for organizations aiming to safeguard their infrastructures from escalating cyber threats.

Source link

Latest articles

Ransomware Attack Disables Doors and HVAC Systems at Canadian Hospital

Experts Highlight Operational Technology Risks Following Ransomware Attack on Canadian Hospital A ransomware attack targeting...

Closing Security Gaps at the Intersection of Digital and Physical Access

Enhancing Access Management in Risk Strategies Amid Evolving Threats Access management stands at the forefront...

Russian-Linked Hackers Breach Polish Power Plant OT via APN

Polish CERT Reports Insights from Cyber-Attack on Energy Infrastructure Amid Russian Campaign The Polish Computer...

Hackers Take Advantage of Serious VMware vCenter Vulnerability to Implement Reverse SSH in 47 Countries

Threat researchers have uncovered an active campaign that exploits a critical vulnerability in VMware...

More like this

Ransomware Attack Disables Doors and HVAC Systems at Canadian Hospital

Experts Highlight Operational Technology Risks Following Ransomware Attack on Canadian Hospital A ransomware attack targeting...

Closing Security Gaps at the Intersection of Digital and Physical Access

Enhancing Access Management in Risk Strategies Amid Evolving Threats Access management stands at the forefront...

Russian-Linked Hackers Breach Polish Power Plant OT via APN

Polish CERT Reports Insights from Cyber-Attack on Energy Infrastructure Amid Russian Campaign The Polish Computer...