A joint advisory from U.S. and Republic of Korea authorities has warned that the Gunra ransomware-as-a-service (RaaS) operation is actively exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organizations. The advisory, issued on August 10, was authored by the FBI, CISA, and other U.S. government agencies, alongside the Republic of Korea’s National Police Agency (KNPA).
Gunra, which first appeared in April 2025 and is based on leaked Conti ransomware source code from 2022, developed a structured RaaS affiliate program in early 2026, advertised on dark web forums. The group has also adopted new aliases, including "Golden Community."
The FBI has observed Gunra specifically targeting two legacy Fortinet authentication bypass vulnerabilities affecting FortiOS and FortiProxy versions. CVE-2024-55591 is a critical flaw that allows a remote attacker to gain super-admin privileges through crafted requests to a Node.js websocket module. CVE-2025-24472 is a high-severity vulnerability that can allow a remote unauthenticated attacker, with prior knowledge of upstream and downstream device serial numbers, to gain super-admin privileges on a downstream device if the Security Fabric is enabled, via crafted CSF proxy requests. Patches are available for both vulnerabilities.
Following initial access, Gunra actors are adept at establishing persistence and achieving lateral movement within victim environments, often bypassing authentication protocols. In one observed instance, the group gained access to an administrator account for an SSL-VPN appliance by exploiting default credentials where account lockout controls were absent. They then established connections to an external attacker-controlled server by downloading the SSH tunneling tool OpenSSH. In another case, attackers modified authentication processing files on a corporate VDI authentication portal server to continuously bypass multi-factor authentication (MFA).
Gunra employs stealth and defense impairment techniques to hinder detection and analysis while moving across networks using stolen credentials and authentication bypass methods. These techniques include deleting system and network access logs and clearing command history. The group primarily conducts malicious activities and internal infrastructure reconnaissance between 10:00 PM and 6:00 AM in the victim’s time zone, when administrators are typically offline.
The group also focuses on exfiltrating large volumes of data from victim environments before detection, enabling a double-extortion strategy. The ransomware binary includes extensive filtering rules to target only user data, avoiding non-critical files and streamlining the collection of sensitive information. The FBI has observed Gunra actors using a malicious executable to exfiltrate data from Microsoft OneDrive and SharePoint. In at least one case, attackers successfully exfiltrated tens of terabytes of data by generating compressed archives of sensitive information and transferring them to the file-sharing service Mega.
Gunra's ransom demands typically begin in the tens of millions of dollars, described as "arbitrarily high." Victims are usually given five to seven days to initiate negotiations via a Tor-based portal. The group has also attempted to communicate directly with management staff at victim organizations via email. Threats of data publication on Gunra’s data leak site are made if victims fail to engage or make a payment. Victims have been observed across various critical sectors globally, including healthcare, financial services, government organizations, and critical manufacturing.
The advisory urged organizations to prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure. It also recommended implementing and testing offline, immutable backups stored in a physically separate, segmented location to ensure recoverability without ransom payment, and segmenting networks to restrict lateral movement from an initially compromised device to other systems.






