A joint warning from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s National Police Agency has revealed a serious new attack from the Gunra ransomware group. They are using known Fortinet VPN flaws to get past multi-factor authentication and steal sensitive company data before locking up the victim’s networks.
Gunra appeared in April 2025 as a type of ransomware that forces payments and is thought to be based on stolen source code. By early 2026, the group grew into a complete ransomware service, giving partners a control panel, a customizable ransomware tool, and multi-platform locker files through dark web sites.
Exploits Fortinet Flaws
Gunra affiliates mostly get into systems by taking advantage of known flaws in internet-connected VPN and firewall devices, especially CVE-2024-55591 and CVE-2025-24472, which are flaws that allow bypassing authentication in certain FortiOS and FortiProxy versions.
In one case, actors compromised an SSL-VPN admin account that had weak default passwords and no lockout rules. They changed the authentication files on a company VDI portal so that a Gunra-approved one-time password would always work, getting rid of MFA security completely.
Gunra operators use Impacket tools like psexec.py, smbclient.py, and secretsdump.py to navigate networks through SMB. They can also extract credentials from domain controllers, allowing pass-the-hash and pass-the-ticket attacks.
The group has grabbed VPN traffic to take session cookies, which lets them take over real user sessions. They also stole a symmetric encryption key from a server to decode many saved company passwords.
Gunra sticks to its double-extortion plan by taking data out before using its encryptor. The group uses a special tool called main.exe to steal files from Microsoft OneDrive and SharePoint. They have sent large compressed files, sometimes up to tens of terabytes, to the file-sharing site Mega. Free tools like 7-Zip, RClone, and FileZilla help with this collection and transfer task.
The final payload uses ChaCha20 and RSA-4096 encryption with a multi-threaded setup. It adds the .ENCRT extension to locked files and leaves a ransom note, R3ADM3.txt, in each affected folder.
Victims are directed to a Tor negotiation site or the secure messaging app qTox. They usually have five to seven days before Gunra warns that it will leak or sell the stolen data on its leak site.
The advisory tells organizations, especially in healthcare, finance, manufacturing, transport, and government, to focus on updating internet-connected VPN and RDP systems, keep secure backups in separate places, and use network segmentation to limit risks.
Gunra has shown that it can get around MFA by messing with authentication files. So, security teams should check VPN and VDI login methods for any bad changes. They should also watch for IP addresses, domains, and file hashes linked to Gunra that are mentioned in the CISA advisory.
InfoSecBulletin Cybersecurity for mankind
