Wednesday , August 12 2026
gunra ransomware

Gunra Ransomware Leverage Fortinet VPN Flaws to Evade MFA Obtaining Enterprise Data

A joint warning from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s National Police Agency has revealed a serious new attack from the Gunra ransomware group. They are using known Fortinet VPN flaws to get past multi-factor authentication and steal sensitive company data before locking up the victim’s networks.

Gunra appeared in April 2025 as a type of ransomware that forces payments and is thought to be based on stolen source code. By early 2026, the group grew into a complete ransomware service, giving partners a control panel, a customizable ransomware tool, and multi-platform locker files through dark web sites.

AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

A serious security flaw in Zoom might let a hacker take control of someone else's device in a live meeting...
Read More
AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

Hacker Actively Exploit SonicWall and SharePoint Flaws

The CISA in the U.S. has added two important SonicWall SMA1000 flaws—CVE-2026-15409 and CVE-2026-15410-to its list of Known Exploited Vulnerabilities...
Read More
Hacker Actively Exploit SonicWall and SharePoint Flaws

Gunra Ransomware Leverage Fortinet VPN Flaws to Evade MFA Obtaining Enterprise Data

A joint warning from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service,...
Read More
Gunra Ransomware Leverage Fortinet VPN Flaws to Evade MFA Obtaining Enterprise Data

Hackers accessed a US defense manufacturer’s Microsoft 365 account via phishing.

Attackers penetrated into IEH Corporation, a US defense and airspace firm, using a fake link that looked like a real...
Read More
Hackers accessed a US defense manufacturer’s Microsoft 365 account via phishing.

Google Play Apps Utilize Stealth Loaders to Spread Anatsa Banking Malware

Android users are reminded that a known app store listing can hold a money threat. Researchers found harmful loaders on...
Read More
Google Play Apps Utilize Stealth Loaders to Spread Anatsa Banking Malware

Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns

The gentlemen ransomware group targets various industries of Bangladesh. In an advisory Bangladesh e-Government Computer Incident Response Team (BGD e-GOV...
Read More
Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns

Around 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer

A group of almost 800 harmful packages was added to the npm registry in a new effort to spread malware...
Read More
Around 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer

Google Chrome 151 Update Fixes 41 Flaws, 6 Critical

Google has launched Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update brings 41 security...
Read More
Google Chrome 151 Update Fixes 41 Flaws, 6 Critical

Swiss gov.t SharePoint incident compromised 200 accounts

Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. The...
Read More
Swiss gov.t SharePoint incident compromised 200 accounts

Azad president, Secretary Post Heads to Contest: ISACA Dhaka Chapter Election

The ISACA Dhaka Chapter Election for 2026–2028 will take place on 8, August-2026. Most of the executive roles are likely...
Read More
Azad president, Secretary Post Heads to Contest: ISACA Dhaka Chapter Election

Exploits Fortinet Flaws

Gunra affiliates mostly get into systems by taking advantage of known flaws in internet-connected VPN and firewall devices, especially CVE-2024-55591 and CVE-2025-24472, which are flaws that allow bypassing authentication in certain FortiOS and FortiProxy versions.

In one case, actors compromised an SSL-VPN admin account that had weak default passwords and no lockout rules. They changed the authentication files on a company VDI portal so that a Gunra-approved one-time password would always work, getting rid of MFA security completely.

Gunra operators use Impacket tools like psexec.py, smbclient.py, and secretsdump.py to navigate networks through SMB. They can also extract credentials from domain controllers, allowing pass-the-hash and pass-the-ticket attacks.

The group has grabbed VPN traffic to take session cookies, which lets them take over real user sessions. They also stole a symmetric encryption key from a server to decode many saved company passwords.

Gunra sticks to its double-extortion plan by taking data out before using its encryptor. The group uses a special tool called main.exe to steal files from Microsoft OneDrive and SharePoint. They have sent large compressed files, sometimes up to tens of terabytes, to the file-sharing site Mega. Free tools like 7-Zip, RClone, and FileZilla help with this collection and transfer task.

The final payload uses ChaCha20 and RSA-4096 encryption with a multi-threaded setup. It adds the .ENCRT extension to locked files and leaves a ransom note, R3ADM3.txt, in each affected folder.

Victims are directed to a Tor negotiation site or the secure messaging app qTox. They usually have five to seven days before Gunra warns that it will leak or sell the stolen data on its leak site.

The advisory tells organizations, especially in healthcare, finance, manufacturing, transport, and government, to focus on updating internet-connected VPN and RDP systems, keep secure backups in separate places, and use network segmentation to limit risks.

Gunra has shown that it can get around MFA by messing with authentication files. So, security teams should check VPN and VDI login methods for any bad changes. They should also watch for IP addresses, domains, and file hashes linked to Gunra that are mentioned in the CISA advisory.

Check Also

BIOS

Critical Dell BIOS & Zimbra Flaws Expose Enterprise Systems

A critical flaw with how Dell saves BIOS passwords lets anyone quickly recover these passwords …