Skip to main content
Emerging ThreatsMalware & Ransomware

Gunra Ransomware Targets Infrastructure with Fortinet, Schneider Electric Exploits

Industrial control room interior with analog and digital equipment, featuring a large control panel and computer workstation.

"Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations," CISA Acting Executive Assistant Director for Cybersecurity, Chris Butera, said.

CVE-2024-5559 and CVE-2025-24472: the entry points

Security agencies in South Korea and the U.S. say Gunra ransomware campaigns have repeatedly used two specific flaws to gain initial access: a Schneider Electric PowerLogic P5 vulnerability (CVE-2024-5559) and a Fortinet FortiOS/FortiProxy vulnerability (CVE-2025-24472). Once an appliance is compromised through those internet-facing flaws, operators deploy Gunra as part of a double-extortion playbook that combines data theft with file encryption.

Techniques observed across intrusions

The actor group behind Gunra favors a layered operational model. Researchers and agencies report the following behaviors and tools as regular parts of Gunra attack chains:

  • Phishing as a primary delivery vector and negotiations conducted via a WhatsApp-themed chat Panel.
  • Lateral movement using Impacket libraries — notably psexec.py and smbclient.py — and credential harvesting with secretsdump.py to extract NTDS password hashes from domain controllers.
  • Log deletion, command-history clearing, and a pattern of conducting reconnaissance and malicious activity predominantly between 10 p.m. and 6 a.m. local time.
  • Data exfiltration from Microsoft OneDrive and SharePoint using an executable named "main.exe" and, in some cases, creating compressed archives of terabytes of data uploaded to the MEGA file‑sharing service.
  • Targeting virtual desktop infrastructure (VDI) environments of IT staff to steal system and network configuration files and, in at least one incident, intercepting session cookies from an SSL‑VPN to hijack user sessions.
  • MFA bypass by tampering with authentication processing files on a corporate VDI authentication portal so that a Gunra‑designated one‑time password (OTP) value is accepted.

RaaS, branding shifts, and a split in cryptographic quality

The operation has matured into a ransomware-as-a-service (RaaS) offering. According to researchers, Gunra launched a formal affiliate program on dark web forums in January 2026 that supplies affiliates with a management panel, a configurable builder, cross-platform locker payloads (Windows and Linux), and documentation. The FBI notes the group has used new aliases such as Golden Community and has recruited penetration testers and self-described ethical hackers to act as initial access brokers, offering a share of ransom profits in return for enterprise access.

Analyses of the tooling reveal uneven quality. Breakglass Intelligence reported in March 2026 that Gunra’s Linux builds contained a "catastrophic cryptographic weakness" enabling recovery of encryption keys and file access, while other components are capable, according to security researcher Rakesh Krishnan, of encrypting very large datasets — up to about 9TB — using stream ciphers like Salsa20 or ChaCha20.

Impacted sectors and geographic footprint

CISA and South Korean authorities say victims span healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. Ransomware.Live data show Gunra first emerged in April 2025 and has listed 51 victims to date. The distribution of those victims skews toward Australia, East Asia, and Europe, with most victims reported in South Korea, Brazil, Spain, Thailand, and Hong Kong. Only three victims have been reported in Canada and the United States so far.

What this means for security teams, procurement leaders, and regulators

  • Security teams: Expect multi-stage intrusions that may begin with an internet-facing appliance exploit and extend into VDI and backup infrastructure. Reports describe credential theft, tampering with authentication logic, backup deletion, and encryption of database servers and NAS systems — all of which argue for segmented networks, hardened VPN/SSL appliances, and monitoring for Impacket activity.
  • Procurement leaders: The pattern of exploitation of specific appliances and third‑party software underscores the need to track vendor advisories and patch schedules closely. The source material ties multiple incidents to both Schneider Electric and Fortinet appliances and to exploitation of a financial security product and AnySign4PC in related campaigns.
  • Regulators: Agencies are already linking Gunra activity to broader campaigns that share tooling and infrastructure with state‑level operations. AhnLab observed shared techniques and possible limited collaboration between a state‑sponsored group and the Gunra actors; South Korea warned of campaigns that used the same financial security software vulnerabilities to deliver malware in 2025 and the first half of 2026.

Gunra's combination of appliance exploits, phishing, session hijacking, MFA tampering, and a commercialized affiliate model makes it a salient example of modern ransomware ecosystems. Agencies recommend a familiar but pressing checklist: keep operating systems, software, and firmware updated; prioritize patching internet‑facing systems; enforce network segmentation; and maintain immutable backups stored physically separate from production systems. Whether these defensive measures can keep pace with continued branding shifts, affiliate recruitment, and tool-sharing among disparate actors remains the concrete question left by the record.

Original story