FBI warns Gunra ransomware hackers are exploiting Fortinet flaws
The fast-growing gang is also recruiting hackers and destroying victims’ backups.

Image by Cybernews.
- Gunra hackers are exploiting known Fortinet flaws to gain access to government and critical infrastructure networks.
- Once inside, attackers steal credentials, bypass MFA and move laterally before deploying ransomware.
- The gang is expanding its affiliate operation, recruiting access brokers and targeting Windows and Linux environments.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A relatively little-known ransomware gang – Gunra – has been globally targeting critical infrastructure sectors, exploiting Fortinet flaws to steal credentials and breach networks – all to pilfer terabytes of sensitive business data from victim organizations, CISA warns.
The new joint cybersecurity advisory was released by the US Cybersecurity and Infrastructure Security Agency and the FBI, in partnership with South Korea’s National Police Agency earlier this week.
US authorities say the sophisticated Gunra gang has been targeting government, healthcare, financial services, manufacturing, transportation, utilities, media and other critical organizations since at least April 2025.
Wasting no time, by January 2026, Gunra had launched its own ransomware-as-a-service (RaaS) affiliate program, advertising its service on dark web hacker forums.
Affiliates who sign the ransowmare deal get their own management panel, a configurable ransomware builder, and access to cross-platform payloads.
Operating indiscriminately and regardless of location, the group has been observed targeting organizations across the Americas, Europe, the Middle East, Africa and Asia-Pacific.
The 21-page advisory says Gunra ransomware is believed to be based on, or heavily influenced by, Conti source code previously leaked in 2022.
Gunra exploits Fortinet flaws
Gunra – which has not been linked to any country of origin so far – is said to “primarily gain initial access through the exploitation of known vulnerabilities in internet-facing devices, including firewall and VPN appliances.”
Two catalogued authentication bypass vulnerabilities identified by the FBI – CVE-2024-55591 and CVE-2025-24472 – affect specific versions of Fortinet’s FortiOS and FortiProxy products.
South Korean authorities have also observed Gunra exploiting credential exposure and SSH access control vulnerabilities in internet-facing VPN gateways to gain unauthorized remote access, the advisory states.
Etay Maor, Vice President of Threat Intelligence at Cato Networks, tells Cybernews that gaining initial access is just the beginning.
“The Fortinet vulnerabilities may have provided Gunra with an initial door into victim environments, but ransomware is never just about the door,” Maor explains.
“Once inside, these attackers stole credentials, moved laterally, bypassed MFA, and ultimately reached critical systems before deploying ransomware,”Maor says.
The FBI says the threat actor has dumped credentials from compromised domain controllers, hijacked legitimate user sessions and, in one case, altered authentication files to continuously bypass multi-factor authentication.
The group then moved laterally into critical systems, including Active Directory servers and virtual desktops used by IT personnel, the FBI warns.
Tens of terabytes stolen
As part of the gang’s double-extortion strategy and before encrypting its victims’ systems, Gunra is known to extract a trove of sensitive files and information, including:
- Business-critical documents
- Databases,
- Personally identifiable information (PII)
- Internal email communications
- System and network configuration information
Furthermore, the group is said to encrypt not just files, but “key assets, including database servers and network-attached storage (NAS) systems.”
In one documented attack, the FBI observed the group exfiltrating victim data directly from Microsoft OneDrive and SharePoint, generating compressed archives, with “the volume of exfiltrated data ranging up to tens of terabytes.”
Once encryption takes place, Gunra threatens to publish or sell the stolen information unless a ransom is paid – typically giving victims five to seven days to negotiate via a Tor-based portal or using qTox, a popular encrypted messaging app among extortion gangs.
The FBI says Gunra’s opening ransom demands have reached in the tens of millions of dollars.
CISA urges patching and network defenses
Initially focused on Windows systems, the FBI says Gunra introduced a Linux variant in mid-2025 as the operation expanded into broader cross-platform attacks.
“Threat actors will use any viable entry point they can find, so organizations need the visibility and controls to detect and stop an attacker before that initial foothold becomes a full-scale ransomware event," Maor says.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
CISA is urging organizations to prioritize patching known exploited vulnerabilities in internet-facing systems, maintain offline immutable backups, and segment networks to prevent attackers from moving deeper into compromised environments.
Meanwhile, Fortinet products have faced repeated targeting in recent months.
In June, security researchers uncovered a working database containing more than 30,000 verified Fortinet usernames and passwords, said to have been compiled entirely by hackers.
The massive credential-harvesting operation – known as “FortiBleed” – was tied to roughly 75,000 attacks on organizations across 194 countries, including banks, hospitals, telecoms, government agencies and energy companies – with hackers targeting Fortinet firewalls and VPN gateways to carry out further attacks.
And in December, attackers were observed actively exploiting two other FortiGate authentication bypass flaws – CVE-2025-59718 and CVE-2025-59719 – to steal credentials and access vulnerable devices.
It's unknown whether the Gunra hacking collective was involved in any of those attacks.
Strong password generator