Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

Critical Infrastructure Under Siege as Gunra Ransomware Gang Exploits Fortinet Flaws

A sophisticated ransomware-as-a-service (RaaS) operation is wreaking havoc on critical infrastructure targets worldwide, exploiting known vulnerabilities in firewalls and VPN appliances to bypass even the most robust defenses. The Gunra gang, which emerged in spring 2025, has been using leaked Conti code and outdated flaws in Fortinet products to compromise sensitive systems.

At the heart of the problem are two exploited vulnerabilities: CVE-2024-55591, a critical authentication bypass flaw in FortiOS and FortiProxy that can grant an attacker “super admin” privileges; and CVE-2025-24472, a high-severity flaw impacting FortiOS and FortiProxy software. These weaknesses have been extensively targeted by ransomware actors since their disclosure, yet many organizations remain unpatched.

Gunra’s tactics are nothing short of brazen. In one attack, the gang took control of an SSL-VPN appliance, using its traffic control functionality to collect employees’ login credentials and session information for a corporate virtual desktop infrastructure (VDI) portal. The attackers then leveraged this data to bypass multifactor authentication (MFA) and gain access to sensitive systems.

Moreover, the gang has been observed deleting backups and archived data stored at both primary and disaster recovery centers before and after deploying ransomware. This is a chilling reminder that even organizations with robust backup protocols are not immune to these types of attacks.

The Gunra gang’s modus operandi is centered around exploiting reusable authentication material, as noted by Picus Security research engineer Umut Bayram in a recent blog post. The gang seeks out vulnerabilities in identity and access management infrastructure, including OS credential dumping and compromising access control servers. This emphasis on targeting authentication mechanisms highlights the importance of securing these systems.

The impact of Gunra’s attacks has been far-reaching, with critical infrastructure targets across various sectors and countries hit by the ransomware gang. Government agencies, healthcare organizations, financial services providers, and manufacturing companies have all fallen prey to the gang’s tactics.

In light of this threat, it is essential for organizations to take immediate action to secure their systems. This includes patching known vulnerabilities, implementing robust identity and access management protocols, and closely monitoring authentication mechanisms for suspicious activity. By staying vigilant and proactive, organizations can mitigate the risk of falling victim to Gunra’s brazen attacks.


Source: Dark Reading — 2026-08-11