CyberSecurity SEE

Gunra Ransomware Targets Critical Infrastructure by Exploiting Fortinet Vulnerabilities

Gunra Ransomware Targets Critical Infrastructure by Exploiting Fortinet Vulnerabilities

Gunra Ransomware Targets Government and Critical Infrastructure: Joint Advisory Issued by US and South Korean Authorities

Recent warnings from the FBI and South Korean authorities highlight the increasing threat posed by Gunra ransomware, which is actively exploiting two vulnerabilities in Fortinet security solutions to target government entities and critical infrastructure organizations. This joint advisory brings to light the advanced methods employed by Gunra affiliates to infiltrate systems, adding urgency to cybersecurity measures across sectors.

Gunra represents a new wave in ransomware-as-a-service (RaaS), focusing primarily on exploiting vulnerabilities in internet-facing devices, such as firewalls and VPN appliances. By leveraging these flaws, attackers gain initial access to their targets, setting the stage for subsequent maneuvers within those networks. Once inside, they utilize sophisticated persistence techniques and lateral movement tactics to stealthily exfiltrate vast amounts of sensitive data, particularly from Microsoft 365 services.

The advisory, a collaborative effort by US agencies such as the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI, alongside South Korea’s National Police Agency (KNPA), paints a sobering picture of the Gunra threat landscape. Originally observed in April 2025, the ransomware is based on the leaked source code of the notorious Conti ransomware, which became available in early 2022. By early 2026, Gunra had developed a structured affiliate program promoted on dark web forums, adopting new branding, including the alias "Golden Community."

Exploiting Legacy Vulnerabilities in Fortinet Devices

In its investigations, the FBI has identified that Gunra particularly targets two specific vulnerabilities in legacy Fortinet systems. These include:

  1. CVE-2024-55591: A critical flaw that enables remote attackers to acquire super-admin privileges through crafted requests to the Node.js websocket module.

  2. CVE-2025-24472: A high-severity vulnerability allowing an unauthenticated remote attacker with knowledge of device serial numbers to gain elevated privileges on downstream devices if the Security Fabric feature is enabled.

Both vulnerabilities have available patches, yet the advisory emphasizes that simply applying these fixes does not guarantee security. Jacob Krell, a senior director at Suzu Labs, noted that while patching closes off the vulnerability path, it may not eliminate existing backdoors that allow attackers to maintain access.

An alarming case cited in the advisory involved Gunra actors exploiting default credentials on a secure socket layer (SSL)-VPN appliance, demonstrating their capability to access administrator accounts easily. Following this, they created connections between compromised systems and an attacker-controlled external server, using the SSH tunneling tool OpenSSH. The advisory also described an incident where attackers bypassed multi-factor authentication (MFA) by modifying authentication processing files on a corporate Virtual Desktop Infrastructure (VDI) server.

Stealthy Exfiltration Techniques

Gunra’s aggressive approach to data exfiltration is noteworthy. It operates on a double-extortion model, compelling victims to pay not only for data decryption but also to prevent the disclosure of stolen data online. The advisory explains that the group employs various stealth techniques to enhance their undetected movements within victim networks. For instance, they intentionally delete system and network access logs to obscure their tracks, often conducting their malicious activities during off-peak hours when organizational defenses might be lower.

Roman Sannikov, a global research coordinator at iCOUNTER, advised security teams to be vigilant regarding Gunra’s out-of-hours activities, which are inherently designed to exploit periods of reduced oversight.

The group’s sophisticated ransomware binary includes extensive filtering rules that focus solely on user data, thereby optimizing resource allocation during the encryption process. As part of their data exfiltration strategy, the FBI reported instances where Gunra utilized malicious executables to siphon off sensitive information from platforms like Microsoft OneDrive and SharePoint, achieving exfiltrations amounting to tens of terabytes.

Gunra’s Ransom Demands and Global Impact

Gunra’s ransom demands are alarmingly high, often starting in the tens of millions of dollars, a figure described as "arbitrarily high." Victims usually have a window of five to seven days to initiate negotiations through a Tor-based portal. There have been instances where Gunra even directly reached out to managerial staff within targeted organizations to discuss negotiations, further emphasizing their aggressive tactics.

Victims of Gunra’s attacks span multiple global regions and sectors, including healthcare, financial services, government agencies, and critical manufacturing. This widespread targeting serves as a stark reminder of the vulnerabilities that persist across industries.

Strategies to Defend Against Gunra

In response to the growing threat posed by Gunra, the joint advisory outlines essential strategies organizations should adopt:

  1. Prioritizing Patching: Proactively applying patches for known vulnerabilities in internet-facing systems, especially VPN gateways and exposed remote desktop protocols.

  2. Implementing Immutable Backups: Maintaining offline, immutable backups stored in segmented locations to ensure organizational recoverability without meeting ransom demands.

  3. Network Segmentation: Structuring networks in such a way as to limit lateral movement opportunities for attackers who gain initial access.

In summary, the advisory issued by US and South Korean authorities underscores the pressing need for organizations to bolster their cybersecurity measures against the evolving threat landscape posed by Gunra ransomware. It highlights not only the sophisticated tactics employed by the ransomware group but also the critical importance of proactive measures in defending against such persistent threats. By implementing recommended strategies and remaining vigilant, organizations can protect themselves against the sophisticated escape routes utilized by ransomware actors today.

Source link

Exit mobile version