An alarming joint advisory from prominent cybersecurity entities, including the FBI, CISA, and the NSA, has highlighted a critical threat posed by the Gunra ransomware group. This notorious group is leveraging vulnerabilities in Fortinet VPN systems to bypass multi-factor authentication (MFA) and exfiltrate sensitive data from enterprises before encrypting their networks.
Emerging in April 2025, Gunra is a sophisticated ransomware operation that evolved from the leaked Conti source code. By early 2026, it transformed into a ransomware-as-a-service model, offering tools like a management panel and ransomware builder to its affiliates through dark web platforms.
Exploitation of Fortinet VPN Flaws
Investigations reveal that Gunra affiliates primarily gain access by targeting known vulnerabilities in VPN and firewall systems, specifically CVE-2024-55591 and CVE-2025-24472. These flaws facilitate authentication bypass in specific FortiOS and FortiProxy versions.
In documented attacks, Gunra operators compromised SSL-VPN administrator accounts using default credentials lacking lockout protections. They manipulated authentication files on corporate portals to ensure a predefined one-time password consistently bypassed MFA, rendering it ineffective.
Advanced Network Penetration Techniques
Once inside the network, Gunra employs Impacket tools like psexec.py and secretsdump.py to traverse systems, execute pass-the-hash, and pass-the-ticket attacks. The group also intercepts VPN communications to capture session cookies for session hijacking.
In some instances, Gunra extracted encryption keys from access control servers to decrypt stored passwords, highlighting their capability to execute complex cyber espionage.
Data Exfiltration and Extortion Tactics
Before deploying encryption, Gunra siphons data using custom tools such as main.exe, targeting cloud storage like Microsoft OneDrive. They utilize utilities like 7-Zip to compress and transfer data to platforms like Mega, often amounting to terabytes.
The ransomware encrypts files using ChaCha20 and RSA-4096 algorithms, appending a .ENCRT extension and distributing ransom notes across affected directories. Victims face a five to seven-day window to negotiate through a Tor-based portal or qTox app, under threat of data leaks.
The advisory strongly recommends that sectors such as healthcare, finance, and government patch vulnerable systems, maintain offline backups, and enforce network segmentation to mitigate such threats. Organizations should audit VPN and VDI authentication systems and monitor for Gunra-related indicators as outlined in the CISA advisory.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. Integrate ANY.RUN With Your SOC Now.
