ransomware
~/ › ransomware › article
Gunra Ransomware Exploits Fortinet Zero-Days
> By Haider | Aug 12, 2026 | 4 min read
A joint cybersecurity advisory issued by CISA, the FBI, and South Korea’s National Police Agency has exposed the rapid proliferation of the Gunra Ransomware family. Identified by threat intelligence analysts as a direct descendant of the notorious Conti source code, Gunra Ransomware operates on a highly aggressive Ransomware-as-a-Service (RaaS) model. Their affiliates are actively targeting critical infrastructure, logistics, and healthcare networks, causing widespread operational paralysis across Europe and Asia.

> TABLE_OF_CONTENTS [toggle]
Exploitation of Fortinet and System Destruction Tactics
The affiliates execute their initial access phase by indiscriminately scanning for and exploiting two specific internet-facing appliance vulnerabilities: CVE-2024-55591 and CVE-2025-24472. These authentication-bypass flaws in Fortinet FortiOS and FortiProxy allow attackers to hijack VPN gateways and establish robust internal footholds. They also actively leverage credential exposure and SSH security flaws in unpatched perimeter systems.
Once lateral movement is achieved, the threat actors execute a pre-encryption destruction routine. They systematically target and destroy Volume Shadow Copies (VSS) and localized system backups via heavily obfuscated PowerShell scripts. Following the destruction of recovery mechanisms, the primary ransomware payload executes, encrypting critical databases and massive Network Attached Storage (NAS) units.
- Threat Actor: Gunra Ransomware (Conti-derived RaaS).
- Initial Access Vector: Fortinet Auth-Bypass (CVE-2024-55591, CVE-2025-24472).
- Secondary Targets: High-capacity NAS and hypervisor datastores.
- Attribution Overlap: South Korean intelligence indicates shared operational tooling and C2 infrastructure with the Lazarus Group APT.
Alarmingly, South Korean intelligence agencies have identified significant overlap in the bespoke command-line tools and C2 server infrastructure utilized by the Gunra Ransomware operators and the Lazarus Group. This anomaly suggests a potential tactical collaboration or a shared underground resource pool between financially motivated cybercriminals and state-sponsored espionage units.
Defensive Posture & OT Mitigation Strategies
Defending against these edge-exploitation vectors requires an aggressive patching and segmentation strategy:
- Remediate Known Exploited Vulnerabilities (KEV): Immediate patching of Fortinet appliances is absolutely mandatory. Any FortiOS or FortiProxy instance exposed to the internet must be upgraded to a patched release immediately to neutralize the authentication-bypass vector.
- CTI-Grade OT Mitigation (CRITICAL): For environments managing physical infrastructure (hospitals, logistics hubs), DO NOT rely on generic IT defense. Enforce the Purdue Reference Architecture, ensuring strict OT/IT network isolation (air-gapping). Deploy ICS-specific Deep Packet Inspection (DPI) to identify lateral movement.
- Implement Secure Remote Access (SRA): Phishing-resistant Multi-Factor Authentication (MFA) must be enforced across all VPN and remote access portals. Disable all legacy authentication protocols (like basic SSH without keys) on perimeter appliances.
Strategic Threat Landscape & Ransomware-as-a-Service (RaaS) Economics
The escalation of this specific cyber incident reflects a broader, systemic shift in the global threat landscape regarding ransomware operations. Threat intelligence analysts continuously observe that the tactics, techniques, and procedures (TTPs) deployed here are rapidly becoming the standard blueprint for financially motivated syndicates operating under the Ransomware-as-a-Service (RaaS) model.
In recent months, the proliferation of Initial Access Broker (IAB) networks on dark web forums has drastically reduced the barrier to entry for executing sophisticated intrusions. Instead of developing custom exploits, affiliates are increasingly purchasing pre-compromised credentials or leasing access to vulnerable perimeter infrastructure. This commoditization enables highly aggressive, scalable operations against critical infrastructure, logistics, and healthcare networks.
We are witnessing a significant pivot towards “double” and “triple” extortion campaigns. Threat actors are no longer merely encrypting data; they are exfiltrating highly sensitive corporate intelligence to leverage for public shaming, regulatory pressure, or direct extortion of the compromised entity’s clients and stakeholders.
The Evolution of Defense Evasion & Zero-Trust Architecture
From a defensive standpoint, traditional perimeter security models are demonstrably insufficient. The rapid exploitation of zero-day vulnerabilities in enterprise VPNs and firewall appliances demonstrates that edge devices themselves have become primary targets.
To combat this evolving threat matrix, organizations must urgently transition to a strict Zero-Trust Architecture (ZTA). This requires continuous authentication, rigorous network micro-segmentation, and the deployment of behavior-based Endpoint Detection and Response (EDR) agents to detect lateral movement and pre-encryption destruction routines.
The information provided in this article is for educational and threat intelligence purposes only. CyberAsia does not condone, promote, or encourage any illegal activities. The claims reported herein are based on open-source intelligence published by threat actors on dark web and encrypted channels.
Join 5,000+ analysts. Get uncensored threat intelligence and breach alerts delivered directly to your inbox. Privacy Policy.
Mitigation & Prevention Strategies
Given the dual-extortion tactics often employed by modern ransomware operators, reactive backups are no longer sufficient. Organizations must adopt proactive measures:
- Zero Trust Architecture: Enforce strict network segmentation to limit lateral movement. Ransomware often exploits flat networks to reach critical domain controllers.
- MFA & Credential Hygiene: Mandate Multi-Factor Authentication (MFA) across all administrative accounts and VPN gateways to block initial access brokers.
- Immutable Backups: Maintain offline, immutable backups that cannot be encrypted or deleted by compromised administrative accounts.
> INTELLIGENCE_NOTICE
The report above detailing Gunra Ransomware Exploits Fortinet Zero-Days is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for ransomware threats, please refer to our Secure Drop or contact the research desk.
> related_intel --suggest
ransomware
ransomware
Lazarus Group Deploys Troy Backdoor via Fake Recruiters
> read
ransomware