Feds warn Gunra ransomware is exploiting known bugs hit critical infrastructure

Bender1 pts0 comments

Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure

Jump to main content

Search

REG AD

security

Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure

Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data

Carly Page

Carly<br>Page

Published<br>tue 11 Aug 2026 // 15:36 UTC

US cyber agencies are warning critical infrastructure operators to patch their internet-facing kit after Gunra ransomware affiliates were spotted exploiting known vulnerabilities to break into networks.<br>Gunra first surfaced in 2025 and has wasted little time expanding. CISA, the FBI, NSA, Secret Service, and partner agencies in the US and South Korea say it now operates as ransomware-as-a-service, with affiliates attacking organizations worldwide.<br>Targets have included healthcare, financial services, government, professional services, nonprofits, and other critical infrastructure organizations.

REG AD

The attackers have exploited CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in Fortinet's FortiOS and FortiProxy, to gain administrative access through internet-facing appliances.

REG AD

Once inside, Gunra affiliates follow the now-familiar double-extortion playbook: steal data, encrypt systems, and demand payment for a decryptor and a promise not to publish the haul.<br>Negotiations take place through a Tor-based portal, according to the advisory, with victims typically given between five and seven days to cough up before their stolen data is published.<br>"Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to US and international organizations," said Chris Butera, CISA's acting executive assistant director for cybersecurity.<br>Trend Micro first observed Gunra in April 2025, initially targeting Windows systems and borrowing elements from the Conti ransomware operation. The security shop later uncovered a Linux variant, broadening the range of systems its operators could scramble.<br>That Linux version can run as many as 100 encryption threads in parallel and supports partial encryption, allowing attackers to specify how much of individual files should be encrypted. It can also store RSA-encrypted keys in separate keystore files.

MORE CONTEXT

Intel fortifies Foundry with an actual customer: Fortinet

Attackers target critical FortiSandbox flaws as CISA issues patch order

Ctrl+Alt+Oops: FortiBleed criminal's logins stitch two gangs together

Massive password-stealing attack hits 75k Fortinet firewalls

Trend Micro has seen Gunra activity in Turkey, Taiwan, the US, and South Korea. The gang's own leak site casts the net wider, claiming victims in Brazil, Japan, and Canada as well, including manufacturers, healthcare providers, IT companies, and law firms.<br>The agencies are urging potential targets to patch known exploited vulnerabilities in internet-facing systems, secure VPN gateways and RDP access with multifactor authentication, segment networks, and maintain offline, immutable backups to make life harder for attackers who get through the front door. ®

cyber-crime<br>fortinet<br>ransomware

REG AD

security

DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi

This is why we can't have nice things, people

SYSTEMS

Intel upsizes stock sale to $20B with spending plans still fuzzy

Semiconductor giant says opaquely it will use the proceeds for 'general corporate purposes'

paas and iaas

Why hybrid clouds break and what to do about it

SPONSORED EXPLAINER: There's nothing wrong with hybrid cloud. It's the one-size-fits-all strategy on top of it that's the problem.

Security

Two wars and a World Cup lead to epic DDoS attacks on publishers

Ukraine, Iran, and football inspire geopolitically motivated DDoS attacks, while 1 Tbps traffic jams up 519 percent

COLUMNISTS

Smart glasses are only smart if we train them to be good. Then they'll be fantastic

Just add smart humans – and a pinch of dog

security

Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure

Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data

MOST POPULAR

security

Ransomware gangs skip the CEO, head straight for the 40-something IT manager

OS PLATFORMS

Linus Torvalds says AI has made 'huge' Linux kernel updates the new normal

Security

Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks

networks

‘Humans will be a rounding error on the internet’ says Cloudflare exec

APPLICATIONS

Microsoft tosses Teams Live chat into its feature graveyard

AI

Ai and ML

Anthropic pledges to embed watermarks to help discern AI slop in sop to EU

EU rules cited as reason for effort to trace AI output ancestry

AI and ML

The future is for billionaires – the rest of us will get open weight AI models, maybe

Mark Zuckerberg muses about...

gunra ransomware known critical security internet

Related Articles