Tuesday , September 1 2026
gunra ransomware

Gunra Ransomware Leverage Fortinet VPN Flaws to Evade MFA Obtaining Enterprise Data

A joint warning from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s National Police Agency has revealed a serious new attack from the Gunra ransomware group. They are using known Fortinet VPN flaws to get past multi-factor authentication and steal sensitive company data before locking up the victim’s networks.

Gunra appeared in April 2025 as a type of ransomware that forces payments and is thought to be based on stolen source code. By early 2026, the group grew into a complete ransomware service, giving partners a control panel, a customizable ransomware tool, and multi-platform locker files through dark web sites.

CISA alerts on multiple PaperCut NG/MF flaws being actively exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed two flaws in PaperCut NG and PaperCut MF in its...
Read More
CISA alerts on multiple PaperCut NG/MF flaws being actively exploited

Fire Ant hackers convert Cisco routers into spy platforms

The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco...
Read More
Fire Ant hackers convert Cisco routers into spy platforms

Five Critical WordPress Flaws Lead to Site Takeover or RCE

Many serious security flaws have been found in WordPress plugins and themes, such as WPMU DEV Dashboard, Avada, TranslatePress, Pods,...
Read More
Five Critical WordPress Flaws Lead to Site Takeover or RCE

700 AI agents united to hack Hugging Face after breaking isolation

700 AI agents supposedly escaped their isolation, created a secret communication channel, and worked together to attack Hugging Face's systems....
Read More
700 AI agents united to hack Hugging Face after breaking isolation

ServiceNow warns of three critical security vulnerabilities

ServiceNow issued security updates for three new serious AI Platform problems that can be used in code injection, SQL injection,...
Read More
ServiceNow warns of three critical security vulnerabilities

100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats

Over 100 tech, cybersecurity, and finance groups have signed an open letter with OpenAI. They want a global increase in...
Read More
100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats

8.7 Million Customers data exposed from 3 Airports 

3 airports in the UK were affected by a "cyber security incident." Hackers got into data belonging to nearly nine...
Read More
8.7 Million Customers data exposed from 3 Airports 

Crack 85 Accounts and Steal 2,500+ Records
8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

A cyberattack using open-source AI tools almost ran on its own. It affected government systems in Asia, compromised into 85...
Read More
Crack 85 Accounts and Steal 2,500+ Records  8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

270+ Zimbra servers compromised in continuous attacks

Threat actors have already compromised more than 270 Zimbra instances in attacks that let them run code remotely. These attacks...
Read More
270+ Zimbra servers compromised in continuous attacks

Singapore Approves 200MW Data-Centre Expansion Under Second Call

Singapore has picked four data-centre plans for a total of 200MW of power in its second Data Centre Call for...
Read More
Singapore Approves 200MW Data-Centre Expansion Under Second Call

Exploits Fortinet Flaws

Gunra affiliates mostly get into systems by taking advantage of known flaws in internet-connected VPN and firewall devices, especially CVE-2024-55591 and CVE-2025-24472, which are flaws that allow bypassing authentication in certain FortiOS and FortiProxy versions.

In one case, actors compromised an SSL-VPN admin account that had weak default passwords and no lockout rules. They changed the authentication files on a company VDI portal so that a Gunra-approved one-time password would always work, getting rid of MFA security completely.

Gunra operators use Impacket tools like psexec.py, smbclient.py, and secretsdump.py to navigate networks through SMB. They can also extract credentials from domain controllers, allowing pass-the-hash and pass-the-ticket attacks.

The group has grabbed VPN traffic to take session cookies, which lets them take over real user sessions. They also stole a symmetric encryption key from a server to decode many saved company passwords.

Gunra sticks to its double-extortion plan by taking data out before using its encryptor. The group uses a special tool called main.exe to steal files from Microsoft OneDrive and SharePoint. They have sent large compressed files, sometimes up to tens of terabytes, to the file-sharing site Mega. Free tools like 7-Zip, RClone, and FileZilla help with this collection and transfer task.

The final payload uses ChaCha20 and RSA-4096 encryption with a multi-threaded setup. It adds the .ENCRT extension to locked files and leaves a ransom note, R3ADM3.txt, in each affected folder.

Victims are directed to a Tor negotiation site or the secure messaging app qTox. They usually have five to seven days before Gunra warns that it will leak or sell the stolen data on its leak site.

The advisory tells organizations, especially in healthcare, finance, manufacturing, transport, and government, to focus on updating internet-connected VPN and RDP systems, keep secure backups in separate places, and use network segmentation to limit risks.

Gunra has shown that it can get around MFA by messing with authentication files. So, security teams should check VPN and VDI login methods for any bad changes. They should also watch for IP addresses, domains, and file hashes linked to Gunra that are mentioned in the CISA advisory.

Check Also

cable

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside …