Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
Key Takeaways A new ransomware group, Gunra, is actively exploiting Fortinet VPN vulnerabilities to bypass multi-factor authentication and exfiltrate data. Gunra, which emerged in April 2025 and...
Key Takeaways
- A new ransomware group, Gunra, is actively exploiting Fortinet VPN vulnerabilities to bypass multi-factor authentication and exfiltrate data.
- Gunra, which emerged in April 2025 and operates as a Ransomware-as-a-Service (RaaS), is believed to be built on leaked Conti source code.
- The group utilizes known authentication bypass flaws, CVE-2024-55591 and CVE-2025-24472, in FortiOS and FortiProxy.
- After initial access, Gunra employs tools like Impacket for lateral movement and performs double extortion by exfiltrating data before encryption.
- Federal agencies strongly advise patching critical vulnerabilities, strengthening backup strategies, and auditing authentication mechanisms.
Gunra Ransomware: Exploiting Fortinet VPNs and Bypassing MFA
A comprehensive cybersecurity advisory, issued collaboratively by the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s National Police Agency, has shed light on a dangerous campaign by the Gunra ransomware collective. This group is systematically leveraging known vulnerabilities in Fortinet VPNs to circumvent multi-factor authentication (MFA), exfiltrate sensitive corporate data, and ultimately encrypt victim networks.
Table Of Content
Gunra first appeared on the threat landscape in April 2025, initially identified as a double-extortion ransomware variant. Researchers speculate its development lineage traces back to leaked Conti source code. By early 2026, the operation had matured significantly, transitioning into a full-fledged Ransomware-as-a-Service (RaaS) model. Through dark web forums, Gunra now provides affiliates with a management panel, a customizable ransomware builder, and cross-platform locker payloads.
Further intelligence from the FBI indicates that the group has also been observed operating under the moniker “Golden Community.” This rebranding effort coincides with active recruitment drives for penetration testers and ethical hackers, offering them a share of ransom profits in exchange for their expertise as initial access brokers.
Exploiting Fortinet Vulnerabilities
Investigations confirm that Gunra affiliates primarily gain their initial foothold by exploiting well-documented vulnerabilities in internet-facing VPN and firewall appliances. Specifically, the group targets CVE-2024-55591 and CVE-2025-24472. Both are critical authentication bypass flaws impacting specific versions of FortiOS and FortiProxy.
In one documented incident, threat actors compromised an SSL-VPN administrator account. This account was protected by default credentials and lacked lockout controls, making it an easy target. Following initial access, the attackers modified authentication files on a corporate Virtual Desktop Infrastructure (VDI) portal. This manipulation ensured that a specific, Gunra-designated one-time password value would always grant successful authentication, thereby completely nullifying the intended MFA protections.
Upon establishing an internal presence, Gunra operators extensively deploy Impacket tools, including psexec.py, smbclient.py, and secretsdump.py. These utilities facilitate lateral movement across networks via SMB and enable the dumping of credentials from domain controllers, paving the way for pass-the-hash and pass-the-ticket attacks.
The group has also demonstrated advanced tactics, such as intercepting VPN traffic to steal session cookies, which are then used to hijack legitimate user sessions. In at least one notable instance, they managed to steal a symmetric encryption key from a system access control server, allowing for the mass decryption of stored enterprise passwords.
Data Exfiltration and Encryption
Adhering to its double-extortion strategy, Gunra prioritizes data exfiltration before deploying its encryption payload. The actors employ a custom tool, identified as main.exe, to siphon files from Microsoft OneDrive and SharePoint. Compressed archives, often amounting to tens of terabytes of data, are then transferred to the file-sharing platform Mega. Open-source utilities such as 7-Zip, RClone, and FileZilla are also leveraged to support this data collection and transfer process.
The final encryption payload utilizes a multi-threaded architecture with ChaCha20 and RSA-4096 encryption algorithms. Encrypted files are marked with the .ENCRT extension, and a ransom note, R3ADM3.txt, is deposited in every affected directory.
Victims are typically directed to a Tor-based negotiation portal or the encrypted messaging application qTox. They are generally given a window of five to seven days before Gunra threatens to leak or sell the stolen data on its dedicated leak site.
What You Should Do
- Patch Immediately: Prioritize patching all internet-facing VPN and RDP infrastructure, especially addressing CVE-2024-55591 and CVE-2025-24472 for Fortinet products.
- Strengthen Backups: Implement a robust backup strategy that includes offline and immutable backups stored in segmented, secure locations.
- Enforce Network Segmentation: Utilize network segmentation to limit lateral movement within your network, thereby containing potential breaches.
- Audit Authentication Logic: Regularly audit VPN and VDI authentication logic for any unauthorized modifications or tampering that could bypass MFA.
- Monitor for IoCs: Actively monitor your network for known Gunra-linked IP addresses, domains, and file hashes published in the CISA advisory’s indicators of compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.