Saturday , September 26 2026
gunra ransomware

Gunra Ransomware Leverage Fortinet VPN Flaws to Evade MFA Obtaining Enterprise Data

A joint warning from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s National Police Agency has revealed a serious new attack from the Gunra ransomware group. They are using known Fortinet VPN flaws to get past multi-factor authentication and steal sensitive company data before locking up the victim’s networks.

Gunra appeared in April 2025 as a type of ransomware that forces payments and is thought to be based on stolen source code. By early 2026, the group grew into a complete ransomware service, giving partners a control panel, a customizable ransomware tool, and multi-platform locker files through dark web sites.

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Exploits Fortinet Flaws

Gunra affiliates mostly get into systems by taking advantage of known flaws in internet-connected VPN and firewall devices, especially CVE-2024-55591 and CVE-2025-24472, which are flaws that allow bypassing authentication in certain FortiOS and FortiProxy versions.

In one case, actors compromised an SSL-VPN admin account that had weak default passwords and no lockout rules. They changed the authentication files on a company VDI portal so that a Gunra-approved one-time password would always work, getting rid of MFA security completely.

Gunra operators use Impacket tools like psexec.py, smbclient.py, and secretsdump.py to navigate networks through SMB. They can also extract credentials from domain controllers, allowing pass-the-hash and pass-the-ticket attacks.

The group has grabbed VPN traffic to take session cookies, which lets them take over real user sessions. They also stole a symmetric encryption key from a server to decode many saved company passwords.

Gunra sticks to its double-extortion plan by taking data out before using its encryptor. The group uses a special tool called main.exe to steal files from Microsoft OneDrive and SharePoint. They have sent large compressed files, sometimes up to tens of terabytes, to the file-sharing site Mega. Free tools like 7-Zip, RClone, and FileZilla help with this collection and transfer task.

The final payload uses ChaCha20 and RSA-4096 encryption with a multi-threaded setup. It adds the .ENCRT extension to locked files and leaves a ransom note, R3ADM3.txt, in each affected folder.

Victims are directed to a Tor negotiation site or the secure messaging app qTox. They usually have five to seven days before Gunra warns that it will leak or sell the stolen data on its leak site.

The advisory tells organizations, especially in healthcare, finance, manufacturing, transport, and government, to focus on updating internet-connected VPN and RDP systems, keep secure backups in separate places, and use network segmentation to limit risks.

Gunra has shown that it can get around MFA by messing with authentication files. So, security teams should check VPN and VDI login methods for any bad changes. They should also watch for IP addresses, domains, and file hashes linked to Gunra that are mentioned in the CISA advisory.

Check Also

France

727,000 data exposes: French hospital fined €500,000

France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for …