Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure
Jump to main content
Search
REG AD
security
Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure
Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data
Carly Page
Carly<br>Page
Published<br>tue 11 Aug 2026 // 15:36 UTC
US cyber agencies are warning critical infrastructure operators to patch their internet-facing kit after Gunra ransomware affiliates were spotted exploiting known vulnerabilities to break into networks.<br>Gunra first surfaced in 2025 and has wasted little time expanding. CISA, the FBI, NSA, Secret Service, and partner agencies in the US and South Korea say it now operates as ransomware-as-a-service, with affiliates attacking organizations worldwide.<br>Targets have included healthcare, financial services, government, professional services, nonprofits, and other critical infrastructure organizations.
REG AD
The attackers have exploited CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in Fortinet's FortiOS and FortiProxy, to gain administrative access through internet-facing appliances.
REG AD
Once inside, Gunra affiliates follow the now-familiar double-extortion playbook: steal data, encrypt systems, and demand payment for a decryptor and a promise not to publish the haul.<br>Negotiations take place through a Tor-based portal, according to the advisory, with victims typically given between five and seven days to cough up before their stolen data is published.<br>"Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to US and international organizations," said Chris Butera, CISA's acting executive assistant director for cybersecurity.<br>Trend Micro first observed Gunra in April 2025, initially targeting Windows systems and borrowing elements from the Conti ransomware operation. The security shop later uncovered a Linux variant, broadening the range of systems its operators could scramble.<br>That Linux version can run as many as 100 encryption threads in parallel and supports partial encryption, allowing attackers to specify how much of individual files should be encrypted. It can also store RSA-encrypted keys in separate keystore files.
MORE CONTEXT
Intel fortifies Foundry with an actual customer: Fortinet
Attackers target critical FortiSandbox flaws as CISA issues patch order
Ctrl+Alt+Oops: FortiBleed criminal's logins stitch two gangs together
Massive password-stealing attack hits 75k Fortinet firewalls
Trend Micro has seen Gunra activity in Turkey, Taiwan, the US, and South Korea. The gang's own leak site casts the net wider, claiming victims in Brazil, Japan, and Canada as well, including manufacturers, healthcare providers, IT companies, and law firms.<br>The agencies are urging potential targets to patch known exploited vulnerabilities in internet-facing systems, secure VPN gateways and RDP access with multifactor authentication, segment networks, and maintain offline, immutable backups to make life harder for attackers who get through the front door. ®
cyber-crime<br>fortinet<br>ransomware
REG AD
security
DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi
This is why we can't have nice things, people
SYSTEMS
Intel upsizes stock sale to $20B with spending plans still fuzzy
Semiconductor giant says opaquely it will use the proceeds for 'general corporate purposes'
paas and iaas
Why hybrid clouds break and what to do about it
SPONSORED EXPLAINER: There's nothing wrong with hybrid cloud. It's the one-size-fits-all strategy on top of it that's the problem.
Security
Two wars and a World Cup lead to epic DDoS attacks on publishers
Ukraine, Iran, and football inspire geopolitically motivated DDoS attacks, while 1 Tbps traffic jams up 519 percent
COLUMNISTS
Smart glasses are only smart if we train them to be good. Then they'll be fantastic
Just add smart humans – and a pinch of dog
security
Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure
Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data
MOST POPULAR
security
Ransomware gangs skip the CEO, head straight for the 40-something IT manager
OS PLATFORMS
Linus Torvalds says AI has made 'huge' Linux kernel updates the new normal
Security
Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks
networks
‘Humans will be a rounding error on the internet’ says Cloudflare exec
APPLICATIONS
Microsoft tosses Teams Live chat into its feature graveyard
AI
Ai and ML
Anthropic pledges to embed watermarks to help discern AI slop in sop to EU
EU rules cited as reason for effort to trace AI output ancestry
AI and ML
The future is for billionaires – the rest of us will get open weight AI models, maybe
Mark Zuckerberg muses about...