Skip to main content
Emerging ThreatsMalware & Ransomware

Gunra Ransomware Targets Infrastructure via Fortinet Flaws

Technicians work in a network operations center with modern and legacy equipment, including a Fortinet device.

"CVE-2024-55591 is a critical flaw which allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module."

How Gunra gains initial access via legacy Fortinet flaws

A joint advisory authored by the FBI, the Cybersecurity and Infrastructure Security Agency (CISA) and other U.S. agencies alongside the Republic of Korea’s National Police Agency (KNPA) says Gunra actors are exploiting two legacy Fortinet authentication‑bypass vulnerabilities to gain initial access to government and critical infrastructure networks. The advisory, published on August 10, names the two flaws precisely:

  • CVE-2024-55591 — described as a critical flaw that “allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.”
  • CVE-2025-24472 — characterized as a high‑severity vulnerability that “can allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.”

The advisory notes that patches are available for both flaws. It also stresses that Gunra primarily targets known vulnerabilities in internet‑facing devices such as firewalls and VPN appliances, in keeping with its profile as a ransomware‑as‑a‑service (RaaS) operation that sells access to affiliates.

Persistence, authentication bypasses, and lateral movement

Once inside, Gunra affiliates pursue advanced persistence and lateral movement techniques focused on undermining authentication controls. The advisory describes multiple observed techniques: in one case, attackers exploited default credentials where account lockout controls were absent to obtain an administrator account on an SSL‑VPN appliance, then downloaded the SSH tunnelling tool OpenSSH to establish connections to attacker‑controlled servers.

In another observed instance, attackers modified authentication processing files on a corporate virtual desktop infrastructure (VDI) authentication portal server to enable the continuous bypass of multi‑factor authentication (MFA). The advisory highlights that these persistence mechanisms can remain after the initial vulnerability is patched: as Jacob Krell, senior director, secure AI solutions and cybersecurity at Suzu Labs, put it, “Patching fixes the entry point. It does nothing about an authentication backdoor already embedded in the MFA flow.”

Stealthy exfiltration and tactics to evade defenders

The advisory warns that Gunra actors conduct stealthy reconnaissance and data theft designed to support a double‑extortion model. Attack activity and internal infrastructure reconnaissance primarily occur “between the hours of 10.00pm and 6.00am in the victim’s time zone,” the bulletin says, a pattern Roman Sannikov, global research coordinator at iCOUNTER, singled out: “If your detection coverage drops off overnight, that's exactly the gap this group, now also operating under the alias Golden Community, is built to exploit.”

Gunra employs techniques to impair detection and analysis while moving through networks: deleting system and network access logs, clearing command history, and using stolen credentials or authentication bypasses. The ransomware binary also contains extensive filtering rules to focus encryption and collection on files “consistent with user data,” a design choice intended to save encryption resources and streamline exfiltration of valuable records.

The FBI observed Gunra actors using a malicious executable to exfiltrate data from Microsoft OneDrive and SharePoint. In at least one case, the adversary generated compressed archives of sensitive material and exfiltrated “up to tens of terabytes of data” to the file‑sharing service Mega.

Ransom demands, negotiation practices, and impacted sectors

The advisory describes Gunra’s ransom notes as starting negotiations with demands “in the tens of millions of dollars,” a sum the report calls “arbitrarily high.” Victims are typically given five to seven days to begin negotiations through a Tor‑based portal; the group has also tried to contact management directly via email in some cases. If victims do not engage or pay, Gunra threatens publication of stolen material on its data leak site.

Victims have appeared across multiple regions and sectors, with the advisory listing healthcare, financial services, government organizations and critical manufacturing among those affected.

What this means for technologists, procurement leaders, and affected enterprises

  • Technologists and security teams: prioritize patching of internet‑facing VPN and firewall appliances and review authentication stacks for embedded backdoors or modified processing files. The advisory explicitly recommends patching known exploited vulnerabilities and testing for persistence after remediation.
  • Procurement and IT leadership at affected enterprises: implement and test offline, immutable backups stored “in a physically separate, segmented location” to ensure recoverability without paying ransom, and enforce network segmentation to slow lateral movement from a compromised device.
  • Affected enterprises operating at night: extend and validate detection coverage during the 10.00pm–6.00am window the advisory highlights, and audit log retention and integrity so deletion by attackers can be detected and mitigated.

Gunra represents a clear operational pattern: exploitation of legacy Fortinet authentication bypasses to obtain initial access, followed by hands‑on persistence and stealthy bulk exfiltration tied to an aggressive ransom posture. Patches exist for the named CVEs, but the advisory’s examples and expert comments underline that closing an initial entry point does not guarantee removal of an attacker already embedded in authentication flows or infrastructure. The practical questions for defenders are therefore narrow and immediate: have you patched, have you hunted for post‑exploit persistence in your authentication stack, and can you restore from offline, immutable backups if the worst occurs?

Original advisory and reporting: https://www.infosecurity-magazine.com/news/gunra-ransomware-fortinet-flaws/