Executive Summary
In August 2026, U.S. federal agencies and South Korea's National Policy Agency issued a joint advisory warning government and critical infrastructure organizations worldwide about the Gunra ransomware group's activities. Emerging in April 2025, Gunra utilizes a double-extortion model, encrypting data and threatening public disclosure to coerce ransom payments. The group exploits vulnerabilities in Fortinet firewalls (CVE-2024-55591 and CVE-2025-24472) and SSH access controls in VPN gateways to gain initial access. Initially targeting Windows systems, Gunra expanded to cross-platform attacks with a Linux variant introduced in mid-2025. In January 2026, they launched a ransomware-as-a-service (RaaS) platform, recruiting affiliates and initial access brokers to broaden their reach.
This advisory underscores the escalating threat posed by Gunra, especially to government and critical infrastructure sectors. The group's rapid evolution, from leveraging leaked Conti ransomware code to establishing a RaaS platform, highlights the increasing sophistication and commercialization of ransomware operations. Organizations are urged to patch known vulnerabilities, implement network segmentation, and maintain offline backups to mitigate potential attacks.
Why This Matters Now
The Gunra ransomware group's expansion into a RaaS model and their targeting of critical infrastructure underscore the urgent need for organizations to bolster their cybersecurity defenses against increasingly sophisticated and widespread ransomware threats.
Attack Path Analysis
The Gunra ransomware group exploited critical vulnerabilities in Fortinet devices to gain initial access, escalated privileges to super-admin levels, moved laterally across networks, established command and control channels, exfiltrated sensitive data, and deployed ransomware to encrypt systems, demanding ransom payments.
Kill Chain Progression
Initial Compromise
Description
Gunra exploited authentication bypass vulnerabilities in Fortinet's FortiOS and FortiProxy (CVE-2024-55591 and CVE-2025-24472) to gain unauthorized access to target networks.
Related CVEs
CVE-2024-55591
CVSS 9.8An authentication bypass vulnerability in FortiOS and FortiProxy allows remote attackers to gain super-admin privileges via crafted requests to the Node.js websocket module.
Affected Products:
Fortinet FortiOS – 7.0.0 through 7.0.16
Fortinet FortiProxy – 7.0.0 through 7.0.19, 7.2.0 through 7.2.12
Exploit Status:
exploited in the wildCVE-2025-24472
CVSS 8.1An authentication bypass vulnerability in FortiOS and FortiProxy allows remote attackers to gain super-admin privileges via crafted requests to the CSF proxy.
Affected Products:
Fortinet FortiOS – 7.0.0 through 7.0.16
Fortinet FortiProxy – 7.0.0 through 7.0.19, 7.2.0 through 7.2.12
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Data Encrypted for Impact
Archive Collected Data: Archive via Utility
Application Layer Protocol: Web Protocols
Command and Scripting Interpreter: PowerShell
Obfuscated Files or Information
Indicator Removal: File Deletion
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – System and Application Security
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Primary Gunra ransomware target with critical infrastructure exposure, exploiting Fortinet vulnerabilities and VPN access points requiring immediate segmentation and patching.
Health Care / Life Sciences
High-value ransomware target with HIPAA compliance risks, vulnerable to double-extortion attacks through internet-facing systems and lateral movement across patient networks.
Financial Services
Critical sector facing Gunra's cross-platform attacks targeting banking infrastructure, with PCI compliance violations and credential exposure through compromised VPN gateways.
Information Technology/IT
Infrastructure foundation sector enabling attacks across industries through compromised Fortinet firewalls, SSH vulnerabilities, and ransomware-as-a-service platform expansion targeting managed services.
Sources
- US and South Korea warn of Gunra ransomware targeting govt agencieshttps://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/Verified
- CISA, FBI, and Partners Release Joint Cybersecurity Advisory on Gunra Ransomwarehttps://content.govdelivery.com/accounts/USDHSCISA/bulletins/4244745Verified
- Attackers exploiting critical Fortinet zero-day vulnerabilityhttps://www.techtarget.com/searchsecurity/news/366618095/Attackers-exploiting-critical-Fortinet-zero-day-vulnerabilityVerified
- Fortinet discloses second authentication bypass vulnerabilityhttps://www.techtarget.com/searchsecurity/news/366619314/Fortinet-discloses-second-authentication-bypass-vulnerabilityVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have significantly constrained the Gunra ransomware group's ability to exploit vulnerabilities, escalate privileges, and move laterally within the network, thereby reducing the potential blast radius of the attack.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access would likely be constrained, limiting unauthorized entry points and reducing the risk of exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the risk of gaining super-admin control over devices.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely be constrained, reducing the risk of accessing additional systems and expanding their foothold.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control channels would likely be constrained, reducing the risk of remote management and coordination within the compromised environment.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely be constrained, reducing the risk of sensitive data being transferred to external servers.
The attacker's ability to deploy ransomware would likely be constrained, reducing the risk of critical systems and data being encrypted and rendered inaccessible.
Impact at a Glance
Affected Business Functions
- Network Security Operations
- Data Management
- IT Infrastructure
Estimated downtime: 14 days
Estimated loss: $500,000
Sensitive government and critical infrastructure data, including operational details and confidential communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of ransomware within the network.
- • Deploy East-West Traffic Security controls to monitor and control internal traffic, detecting unauthorized access and movement.
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and block communication with malicious external servers.
- • Ensure Multicloud Visibility & Control to maintain comprehensive oversight of network activities across all environments.
- • Regularly update and patch all systems, especially internet-facing devices, to mitigate known vulnerabilities and prevent exploitation.



