Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft

Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft

Posted on August 10, 2026 By CWS

An alarming joint advisory from prominent cybersecurity entities, including the FBI, CISA, and the NSA, has highlighted a critical threat posed by the Gunra ransomware group. This notorious group is leveraging vulnerabilities in Fortinet VPN systems to bypass multi-factor authentication (MFA) and exfiltrate sensitive data from enterprises before encrypting their networks.

Emerging in April 2025, Gunra is a sophisticated ransomware operation that evolved from the leaked Conti source code. By early 2026, it transformed into a ransomware-as-a-service model, offering tools like a management panel and ransomware builder to its affiliates through dark web platforms.

Exploitation of Fortinet VPN Flaws

Investigations reveal that Gunra affiliates primarily gain access by targeting known vulnerabilities in VPN and firewall systems, specifically CVE-2024-55591 and CVE-2025-24472. These flaws facilitate authentication bypass in specific FortiOS and FortiProxy versions.

In documented attacks, Gunra operators compromised SSL-VPN administrator accounts using default credentials lacking lockout protections. They manipulated authentication files on corporate portals to ensure a predefined one-time password consistently bypassed MFA, rendering it ineffective.

Advanced Network Penetration Techniques

Once inside the network, Gunra employs Impacket tools like psexec.py and secretsdump.py to traverse systems, execute pass-the-hash, and pass-the-ticket attacks. The group also intercepts VPN communications to capture session cookies for session hijacking.

In some instances, Gunra extracted encryption keys from access control servers to decrypt stored passwords, highlighting their capability to execute complex cyber espionage.

Data Exfiltration and Extortion Tactics

Before deploying encryption, Gunra siphons data using custom tools such as main.exe, targeting cloud storage like Microsoft OneDrive. They utilize utilities like 7-Zip to compress and transfer data to platforms like Mega, often amounting to terabytes.

The ransomware encrypts files using ChaCha20 and RSA-4096 algorithms, appending a .ENCRT extension and distributing ransom notes across affected directories. Victims face a five to seven-day window to negotiate through a Tor-based portal or qTox app, under threat of data leaks.

The advisory strongly recommends that sectors such as healthcare, finance, and government patch vulnerable systems, maintain offline backups, and enforce network segmentation to mitigate such threats. Organizations should audit VPN and VDI authentication systems and monitor for Gunra-related indicators as outlined in the CISA advisory.

Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. Integrate ANY.RUN With Your SOC Now.

Cyber Security News Tags:CISA advisory, cyber attacks, Cybersecurity, data theft, enterprise data, FBI, Fortinet VPN, Gunra ransomware, IT security, multi-factor authentication

Post navigation

Previous Post: China-Linked Group Unleashes StormEncryptor Ransomware
Next Post: HP ThinPro Encryption Flaw Risks LUKS Key Exposure

Related Posts

Teaching Claude to Cheat Reward Hacking Coding Tasks Makes Them Behave Maliciously in Other Tasks Teaching Claude to Cheat Reward Hacking Coding Tasks Makes Them Behave Maliciously in Other Tasks Cyber Security News
Let’s Encrypt Temporarily Stops Certificate Issuance After Issue Let’s Encrypt Temporarily Stops Certificate Issuance After Issue Cyber Security News
Urgent Chrome Update Fixes Critical Security Flaws Urgent Chrome Update Fixes Critical Security Flaws Cyber Security News
Dropping Elephant’s Deceptive New Cyber Tactics Unveiled Dropping Elephant’s Deceptive New Cyber Tactics Unveiled Cyber Security News
VirtualBox 7.2 Released With Support for Windows 11/Arm VMs and Bug Fixes VirtualBox 7.2 Released With Support for Windows 11/Arm VMs and Bug Fixes Cyber Security News
LocalGPT: Secure AI Assistant Built with Rust LocalGPT: Secure AI Assistant Built with Rust Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • HP ThinPro Encryption Flaw Risks LUKS Key Exposure
  • Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft
  • China-Linked Group Unleashes StormEncryptor Ransomware
  • Windows WalletService Flaw Could Lead to Privilege Escalation
  • CISA Demands Urgent Fix for Progress LoadMaster Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • HP ThinPro Encryption Flaw Risks LUKS Key Exposure
  • Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft
  • China-Linked Group Unleashes StormEncryptor Ransomware
  • Windows WalletService Flaw Could Lead to Privilege Escalation
  • CISA Demands Urgent Fix for Progress LoadMaster Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark