Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

    August 12, 2026

    Inside the Fake Crypto Startup That Fooled North Korean IT Workers

    August 12, 2026

    Stops Along the Path of Totality

    August 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
    • Inside the Fake Crypto Startup That Fooled North Korean IT Workers
    • Stops Along the Path of Totality
    • Cacao plantations in Liberia encroach into proposed Kwa national park
    • Eni-BP joint venture hires TechnipFMC for another project offshore Angola
    • Millions of US tax dollars sent to rightwing European thinktanks. Did any Trump supporters vote for that? | Arwa Mahdawi
    • How Nigel Farage Ended Up Running Against Count Binface in Clacton
    • US allies say they’re worried about Trump’s clout after Netanyahu rejected deal
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 12, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A burgeoning ransomware-as-a-service (RaaS) operation is using known exploited vulnerabilities in campaigns against critical infrastructure and government organizations around the globe.

    US and South Korean government agencies issued a joint cybersecurity alert on Monday regarding Gunra, a ransomware gang that first emerged in the spring of 2025. Gunra’s ransomware is “a sophisticated double-extortion ransomware variant” based on the leaked source code of the now-defunct Conti gang, according to the advisory.

    Initially, Gunra operators focused on Windows environments before developing a Linux variant and further expanding operations this year. “As of early 2026, Gunra expanded its operations through a structured RaaS affiliate program advertised on Dark Web forums to financially motivated cybercriminals,” the advisory states.

    More importantly, the agencies warned, Gunra actors are exploiting N-day vulnerabilities in firewall and VPN appliances for initial access and circumventing some of the most relied-upon defenses for ransomware threats.

    Related:The Coordination Gap: How Attackers Are Outpacing Law Enforcement

    Gunra Weaponizing Fortinet Flaws

    According to the advisory, the FBI observed Gunra actors using two known exploited vulnerabilities in Fortinet products for initial access. The first, CVE-2024-55591, is a critical authentication bypass flaw in FortiOS and FortiProxy that can allow an attacker to achieve “super admin” privileges in Fortinet appliances. The vulnerability was initially disclosed in January 2025 as a zero-day under exploitation.

    The second, CVE-2025-24472, is a high-severity authentication bypass flaw impacting FortiOS and FortiProxy software that was first disclosed in February 2025. CVE-2025-24472 was added to the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog about a month later, following ransomware attacks that weaponized the flaw.

    Both Fortinet vulnerabilities have been heavily targeted by ransomware actors since then. For example, an emerging gang known as SuperBlack exploited the two flaws in attacks last year. But despite that attention, it appears that organizations in a variety of sectors and countries have yet to patch the flaws.

    Additionally, the FBI observed an attack in which Gunra affiliates took control of an SSL-VPN appliance and used the traffic control functionality to collect credentials and session information for employees authenticating to a corporate virtual desktop infrastructure (VDI) portal. The attackers used the stolen cookies for session hijacking and also leveraged the VDI access to beat the target organization’s multifactor authentication protection.

    Related:Déjà Vu? Meta’s AI Escapes Testing Lab in Hacking Joyride

    “For the same victim, the Gunra actors modified authentication processing files on the corporate VDI authentication portal server to allow successful authentication when a specific, Gunra-designated one time password (OTP) value was entered, thereby enabling the continuous bypass of multi-factor authentication (MFA),” the advisory stated.

    The agencies also cited another attack in which Gunra affiliates deleted backups and archived data stored at both the victim’s primary data center and disaster recovery center before and after ransomware was deployed.

    In a blog post published Tuesday, Picus Security research engineer Umut Bayram emphasized that the ransomware gang “goes after reusable authentication material at every turn.” This includes OS credential dumping and, in one case, compromising a Hiware access control server, stealing the encryption key, and decrypting passwords stored in the database. Therefore, organizations should monitor for suspicious activity around their identity and access management infrastructure.

    Who’s Working with Gunra RaaS?

    Gunra attacks have hit a variety of critical infrastructure targets, including organizations in healthcare, financial services, manufacturing, and transportation, as well as government services. According to the advisory, the gang’s data leak site lists victims in North and South America, Europe, the Middle East, Africa, and the Asia-Pacific region.

    Related:CSS: The Hidden Threat Lurking in Your Inbox

    A report published earlier this year by CloudSEK, which infiltrated Gunra’s affiliate program to collect intelligence on the gang, showed that Brazil and South Korea were the two most heavily targeted regions, followed by Canada and Japan. CloudSEK researchers also noted the RaaS operation attracts financially motivated but perhaps lower-skilled cybercriminals with ready-made ransomware tools.

    “The group significantly lowers the barrier to entry for less-sophisticated threat actors by offering comprehensive affiliate support,” the report stated. “This support includes detailed documentation, a user-friendly management panel, and customizable ransomware builders, facilitating the execution of ransomware attacks.”

    This week’s advisory was authored by the FBI, CISA, the US Department of Defense Cyber Crime Center (DC3), the US National Security Agency (NSA), the US Secret Service, and South Korea’s National Police Agency (KNPA). It’s unclear where Gunra operators hail from, though a recent report from South Korean cybersecurity firm AhnLab linked the group to a state-sponsored threat actor targeting organizations in the country.

    “These commonalities suggest that although the state-sponsored threat group and the Gunra ransomware group appear to be separate threat actors with different ultimate objectives, they may have shared certain techniques, tools, and infrastructure or collaborated to a limited extent during the attacks,” AhnLab’s research team wrote in the report.

    The joint advisory urged organizations to prioritize patching known exploited vulnerabilities in Internet-facing appliances such as VPNs, implement and test offline immutable backups, and implement network segmentation to limit threat actors’ ability to move laterally.

    bypasses exploits flaws Fortinet gang Gunra MFA ransomware
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

    Microsoft releases Windows 10 KB5120249 extended security update

    Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

    Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

    Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

    August 12, 2026

    Inside the Fake Crypto Startup That Fooled North Korean IT Workers

    August 12, 2026

    Stops Along the Path of Totality

    August 12, 2026

    Cacao plantations in Liberia encroach into proposed Kwa national park

    August 12, 2026
    Latest Posts

    I grew up near Andy Burnham. This is what shaped our new PM | Andy Burnham

    July 25, 2026

    The Economic Philosophy of Britain’s Andy Burnham

    July 25, 2026

    Samsung Wallet Will Add Stablecoin Support, Including USDC

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

    August 12, 2026

    Inside the Fake Crypto Startup That Fooled North Korean IT Workers

    August 12, 2026

    Stops Along the Path of Totality

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.