Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
August 10, 2026
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Critical Vulnerability Lets Attackers Bypass MFA in Windows 11 and Entra ID
August 10, 2026
Home/CyberSecurity News/Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
CyberSecurity News

Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA

Key Takeaways A new ransomware group, Gunra, is actively exploiting Fortinet VPN vulnerabilities to bypass multi-factor authentication and exfiltrate data. Gunra, which emerged in April 2025 and...

Emy Elsamnoudy
Emy Elsamnoudy
August 10, 2026 3 Min Read
2 0

Key Takeaways

  • A new ransomware group, Gunra, is actively exploiting Fortinet VPN vulnerabilities to bypass multi-factor authentication and exfiltrate data.
  • Gunra, which emerged in April 2025 and operates as a Ransomware-as-a-Service (RaaS), is believed to be built on leaked Conti source code.
  • The group utilizes known authentication bypass flaws, CVE-2024-55591 and CVE-2025-24472, in FortiOS and FortiProxy.
  • After initial access, Gunra employs tools like Impacket for lateral movement and performs double extortion by exfiltrating data before encryption.
  • Federal agencies strongly advise patching critical vulnerabilities, strengthening backup strategies, and auditing authentication mechanisms.

Gunra Ransomware: Exploiting Fortinet VPNs and Bypassing MFA

A comprehensive cybersecurity advisory, issued collaboratively by the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s National Police Agency, has shed light on a dangerous campaign by the Gunra ransomware collective. This group is systematically leveraging known vulnerabilities in Fortinet VPNs to circumvent multi-factor authentication (MFA), exfiltrate sensitive corporate data, and ultimately encrypt victim networks.

Table Of Content

  • Key Takeaways
  • Gunra Ransomware: Exploiting Fortinet VPNs and Bypassing MFA
  • Exploiting Fortinet Vulnerabilities
  • Data Exfiltration and Encryption
  • What You Should Do

Gunra first appeared on the threat landscape in April 2025, initially identified as a double-extortion ransomware variant. Researchers speculate its development lineage traces back to leaked Conti source code. By early 2026, the operation had matured significantly, transitioning into a full-fledged Ransomware-as-a-Service (RaaS) model. Through dark web forums, Gunra now provides affiliates with a management panel, a customizable ransomware builder, and cross-platform locker payloads.

Further intelligence from the FBI indicates that the group has also been observed operating under the moniker “Golden Community.” This rebranding effort coincides with active recruitment drives for penetration testers and ethical hackers, offering them a share of ransom profits in exchange for their expertise as initial access brokers.

Exploiting Fortinet Vulnerabilities

Investigations confirm that Gunra affiliates primarily gain their initial foothold by exploiting well-documented vulnerabilities in internet-facing VPN and firewall appliances. Specifically, the group targets CVE-2024-55591 and CVE-2025-24472. Both are critical authentication bypass flaws impacting specific versions of FortiOS and FortiProxy.

In one documented incident, threat actors compromised an SSL-VPN administrator account. This account was protected by default credentials and lacked lockout controls, making it an easy target. Following initial access, the attackers modified authentication files on a corporate Virtual Desktop Infrastructure (VDI) portal. This manipulation ensured that a specific, Gunra-designated one-time password value would always grant successful authentication, thereby completely nullifying the intended MFA protections.

Upon establishing an internal presence, Gunra operators extensively deploy Impacket tools, including psexec.py, smbclient.py, and secretsdump.py. These utilities facilitate lateral movement across networks via SMB and enable the dumping of credentials from domain controllers, paving the way for pass-the-hash and pass-the-ticket attacks.

The group has also demonstrated advanced tactics, such as intercepting VPN traffic to steal session cookies, which are then used to hijack legitimate user sessions. In at least one notable instance, they managed to steal a symmetric encryption key from a system access control server, allowing for the mass decryption of stored enterprise passwords.

Data Exfiltration and Encryption

Adhering to its double-extortion strategy, Gunra prioritizes data exfiltration before deploying its encryption payload. The actors employ a custom tool, identified as main.exe, to siphon files from Microsoft OneDrive and SharePoint. Compressed archives, often amounting to tens of terabytes of data, are then transferred to the file-sharing platform Mega. Open-source utilities such as 7-Zip, RClone, and FileZilla are also leveraged to support this data collection and transfer process.

The final encryption payload utilizes a multi-threaded architecture with ChaCha20 and RSA-4096 encryption algorithms. Encrypted files are marked with the .ENCRT extension, and a ransom note, R3ADM3.txt, is deposited in every affected directory.

Victims are typically directed to a Tor-based negotiation portal or the encrypted messaging application qTox. They are generally given a window of five to seven days before Gunra threatens to leak or sell the stolen data on its dedicated leak site.

What You Should Do

  • Patch Immediately: Prioritize patching all internet-facing VPN and RDP infrastructure, especially addressing CVE-2024-55591 and CVE-2025-24472 for Fortinet products.
  • Strengthen Backups: Implement a robust backup strategy that includes offline and immutable backups stored in segmented, secure locations.
  • Enforce Network Segmentation: Utilize network segmentation to limit lateral movement within your network, thereby containing potential breaches.
  • Audit Authentication Logic: Regularly audit VPN and VDI authentication logic for any unauthorized modifications or tampering that could bypass MFA.
  • Monitor for IoCs: Actively monitor your network for known Gunra-linked IP addresses, domains, and file hashes published in the CISA advisory’s indicators of compromise.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVECybersecurityExploitHackerPatchransomwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Anthropic Claude: New Security Feature Automates Agent Access Approvals

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
August 10, 2026
Critical Red Hat ACM Vulnerability Lets Attackers Gain Cluster-Admin Access
August 10, 2026
GitHub Expands Malware Detection to 8 Package Registries
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us