Executive Summary
In August 2026, cybersecurity agencies from South Korea and the U.S. issued warnings about Gunra ransomware attacks targeting critical infrastructure sectors worldwide. The attackers exploited vulnerabilities in Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS and FortiProxy (CVE-2025-24472) appliances to gain initial access. Employing a double extortion model, they encrypted data and exfiltrated sensitive information, threatening to publish it unless a ransom was paid within five to seven days. Since its emergence in April 2025, Gunra has listed 51 victims, primarily in South Korea, Brazil, Spain, Thailand, and Hong Kong. The group utilizes phishing campaigns and advanced encryption methods like Salsa20 and ChaCha20 to execute their attacks.
This incident underscores the evolving tactics of ransomware groups, highlighting the critical need for organizations to promptly patch known vulnerabilities and implement robust security measures to protect against such sophisticated threats.
Why This Matters Now
The Gunra ransomware attacks highlight the urgent need for organizations to address known vulnerabilities in critical infrastructure systems. With ransomware groups increasingly exploiting such flaws, timely patching and comprehensive security strategies are essential to prevent significant operational disruptions and data breaches.
Attack Path Analysis
The Gunra ransomware group exploited vulnerabilities in internet-facing Schneider Electric PowerLogic P5 and Fortinet FortiOS and FortiProxy appliances to gain initial access. They escalated privileges by leveraging authentication bypass flaws, allowing them to obtain super-admin rights. Utilizing tools like Impacket's 'psexec.py' and 'smbclient.py', they moved laterally across the network. Command and control were maintained through the use of Impacket utilities and by deleting system/network access logs to evade detection. Data exfiltration was conducted using an executable named 'main.exe' to extract data from Microsoft OneDrive and SharePoint. Finally, the ransomware was deployed, encrypting critical assets and demanding ransom payments.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploited vulnerabilities in Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS and FortiProxy (CVE-2025-24472) appliances to gain unauthorized access.
Related CVEs
CVE-2025-24472
CVSS 8.1An authentication bypass vulnerability in Fortinet's FortiOS and FortiProxy allows remote attackers to gain super-admin privileges via crafted CSF proxy requests.
Affected Products:
Fortinet FortiOS – 7.0.0 through 7.0.16
Fortinet FortiProxy – 7.0.0 through 7.0.19, 7.2.0 through 7.2.12
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Phishing: Spearphishing Attachment
Valid Accounts
OS Credential Dumping
Remote Services: SMB/Windows Admin Shares
Exfiltration Over C2 Channel
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Gunra ransomware specifically targets healthcare organizations, exploiting Fortinet/Schneider vulnerabilities to deploy double extortion attacks affecting patient data and critical medical infrastructure systems.
Financial Services
Financial institutions face elevated risk from Gunra's exploitation of SSL-VPN appliances and session hijacking capabilities, compromising authentication systems and enabling data exfiltration attacks.
Government Administration
Government facilities are primary Gunra targets, with attackers leveraging credential dumping and lateral movement techniques to compromise critical infrastructure and sensitive government data.
Utilities
Critical infrastructure vulnerability through Schneider Electric PowerLogic exploitation enables Gunra actors to compromise industrial control systems and deploy ransomware across utility networks.
Sources
- Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networkshttps://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.htmlVerified
- CISA, FBI, and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectorshttps://www.cisa.gov/news-events/news/cisa-fbi-and-partners-warn-organizations-gunra-ransomware-actors-targeting-multiple-criticalVerified
- CVE-2025-24472: An Authentication Bypass Using an Alternate Path or Channelhttps://cve.imfht.com/detail/CVE-2025-24472?lang=enVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit vulnerabilities in internet-facing appliances would likely be constrained by enforcing strict access controls and continuous verification.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained by enforcing identity-based access controls and limiting trust relationships.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally would likely be constrained by enforcing strict segmentation and monitoring east-west traffic.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain command and control would likely be constrained by continuous monitoring and visibility across multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data would likely be constrained by enforcing strict egress policies and monitoring outbound traffic.
The attacker's ability to deploy ransomware and encrypt critical assets would likely be constrained by limiting lateral movement and enforcing strict access controls.
Impact at a Glance
Affected Business Functions
- Network Security Management
- Data Storage Systems
- User Authentication Services
Estimated downtime: 14 days
Estimated loss: $5,000,000
Sensitive corporate data, including intellectual property and customer information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of ransomware.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities.
- • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Regularly update and patch all systems to mitigate known vulnerabilities and reduce the attack surface.



