Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft

Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft

Posted on August 10, 2026 By CWS

An alarming joint advisory from prominent cybersecurity entities, including the FBI, CISA, and the NSA, has highlighted a critical threat posed by the Gunra ransomware group. This notorious group is leveraging vulnerabilities in Fortinet VPN systems to bypass multi-factor authentication (MFA) and exfiltrate sensitive data from enterprises before encrypting their networks.

Emerging in April 2025, Gunra is a sophisticated ransomware operation that evolved from the leaked Conti source code. By early 2026, it transformed into a ransomware-as-a-service model, offering tools like a management panel and ransomware builder to its affiliates through dark web platforms.

Exploitation of Fortinet VPN Flaws

Investigations reveal that Gunra affiliates primarily gain access by targeting known vulnerabilities in VPN and firewall systems, specifically CVE-2024-55591 and CVE-2025-24472. These flaws facilitate authentication bypass in specific FortiOS and FortiProxy versions.

In documented attacks, Gunra operators compromised SSL-VPN administrator accounts using default credentials lacking lockout protections. They manipulated authentication files on corporate portals to ensure a predefined one-time password consistently bypassed MFA, rendering it ineffective.

Advanced Network Penetration Techniques

Once inside the network, Gunra employs Impacket tools like psexec.py and secretsdump.py to traverse systems, execute pass-the-hash, and pass-the-ticket attacks. The group also intercepts VPN communications to capture session cookies for session hijacking.

In some instances, Gunra extracted encryption keys from access control servers to decrypt stored passwords, highlighting their capability to execute complex cyber espionage.

Data Exfiltration and Extortion Tactics

Before deploying encryption, Gunra siphons data using custom tools such as main.exe, targeting cloud storage like Microsoft OneDrive. They utilize utilities like 7-Zip to compress and transfer data to platforms like Mega, often amounting to terabytes.

The ransomware encrypts files using ChaCha20 and RSA-4096 algorithms, appending a .ENCRT extension and distributing ransom notes across affected directories. Victims face a five to seven-day window to negotiate through a Tor-based portal or qTox app, under threat of data leaks.

The advisory strongly recommends that sectors such as healthcare, finance, and government patch vulnerable systems, maintain offline backups, and enforce network segmentation to mitigate such threats. Organizations should audit VPN and VDI authentication systems and monitor for Gunra-related indicators as outlined in the CISA advisory.

Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. Integrate ANY.RUN With Your SOC Now.

Cyber Security News Tags:CISA advisory, cyber attacks, Cybersecurity, data theft, enterprise data, FBI, Fortinet VPN, Gunra ransomware, IT security, multi-factor authentication

Post navigation

Previous Post: China-Linked Group Unleashes StormEncryptor Ransomware

Related Posts

Chinese Hackers Organization Influence U.S. Government Policy on International Issues Chinese Hackers Organization Influence U.S. Government Policy on International Issues Cyber Security News
APT28 With Weaponized Office Documents Delivers BeardShell and Covenant Modules APT28 With Weaponized Office Documents Delivers BeardShell and Covenant Modules Cyber Security News
Node.js Developers Face Advanced Social Engineering Threat Node.js Developers Face Advanced Social Engineering Threat Cyber Security News
Steganography in Images: A New Cybersecurity Threat Steganography in Images: A New Cybersecurity Threat Cyber Security News
China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware Cyber Security News
Top 10 Best API Penetration Testing Companies In 2025 Top 10 Best API Penetration Testing Companies In 2025 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft
  • China-Linked Group Unleashes StormEncryptor Ransomware
  • Windows WalletService Flaw Could Lead to Privilege Escalation
  • CISA Demands Urgent Fix for Progress LoadMaster Flaw
  • AI Threats, Metabase 0-Day, and Router Backdoors Highlight Cybersecurity Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft
  • China-Linked Group Unleashes StormEncryptor Ransomware
  • Windows WalletService Flaw Could Lead to Privilege Escalation
  • CISA Demands Urgent Fix for Progress LoadMaster Flaw
  • AI Threats, Metabase 0-Day, and Router Backdoors Highlight Cybersecurity Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark