Gunra: New Ransomware Exploits Fortinet Flaws Against Critical Infrastructure
US and South Korean agencies warn of Gunra's rapid expansion, already operating as RaaS and compromising key sectors through known vulnerabilities.
August 14, 2026 · 4 min read
TL;DR: Gunra is a ransomware that operates as RaaS and exploits known Fortinet vulnerabilities to attack critical infrastructure. US and South Korean agencies warn of its rapid expansion and recommend patching and strengthening perimeter security.
The ransomware landscape has a new threat that has put cybersecurity agencies in the United States and South Korea on alert. Gunra, a ransomware that emerged in 2025, is being used by affiliates to compromise networks of critical infrastructure, exploiting known vulnerabilities in Fortinet products. The joint advisory issued by CISA, FBI, NSA, Secret Service, and allied agencies underscores the urgency of patching internet-exposed systems and adopting defense-in-depth measures.
What happened?
Gunra was first detected in April 2025 by Trend Micro, initially targeting Windows systems and taking elements from the well-known Conti ransomware. Shortly after, researchers found a Linux variant, significantly expanding the range of systems its operators could encrypt. This Linux version is especially powerful: it can run up to 100 encryption threads in parallel and supports partial encryption, allowing attackers to specify which part of each file is encrypted. Additionally, it stores RSA keys in separate files, making recovery difficult without the decryptor.
The group has rapidly evolved into a ransomware-as-a-service (RaaS) model, attracting affiliates who launch attacks against organizations worldwide. According to the advisory, affected sectors include healthcare, financial services, government, professional services, non-profits, and other critical infrastructure. Activity has been observed in Turkey, Taiwan, the United States, and South Korea, although the group's leak site claims victims in Brazil, Japan, and Canada, among others.
Exploited vulnerabilities
The initial access vector is two authentication vulnerabilities in Fortinet: CVE-2024-55591 and CVE-2025-24472. These flaws allow attackers to gain administrative privileges on internet-exposed FortiOS and FortiProxy devices. Although these are known and patched vulnerabilities, many organizations have not applied updates, leaving the door open for Gunra affiliates. This pattern is recurrent in ransomware: exploiting known flaws remains the most effective method to compromise networks.
Modus operandi
Once inside, affiliates follow the well-known double extortion playbook: they exfiltrate sensitive data, encrypt systems, and demand a ransom in exchange for the decryptor and a promise not to publish the stolen information. Negotiations are conducted through a Tor portal, and victims typically have between five and seven days to pay before data is published. This time pressure aims to maximize the likelihood of payment, especially in critical organizations where service disruption has severe consequences.
Importance and context
The emergence of Gunra is not an isolated event but part of a growing trend of attacks targeting critical infrastructure. Chris Butera, acting executive director of cybersecurity at CISA, noted that Gunra is another variant in the current trend of ransomware causing disruption and harm to US and international organizations. This joint advisory reflects increasingly close international cooperation to combat cybercrime, but it also highlights the persistence of unpatched vulnerabilities in critical systems.
Gunra's evolution, from a Windows-targeting malware to a RaaS operation with a Linux variant, shows the professionalization of the ransomware ecosystem. Affiliates leverage pre-existing infrastructure and code, such as Conti's legacy, to launch large-scale campaigns at minimal cost. This poses a significant challenge for defenses, which must anticipate both known tactics and new variants.
Consequences and recommendations
Agencies urge organizations to immediately patch known vulnerabilities in internet-exposed systems, secure VPN gateways and RDP access with multi-factor authentication, segment networks, and maintain offline and immutable backups. These measures not only hinder initial access but also limit the impact of a compromise and facilitate recovery without paying ransoms.
For the critical infrastructure sector, the threat is especially severe due to potential disruption of essential services. Operators should consider that paying the ransom does not guarantee data recovery or prevent publication, and it also funds future attacks. Prevention and preparedness are the best defenses.
Implications for the future
The rapid expansion of Gunra is a reminder that ransomware remains one of the greatest threats to the digital economy. The combination of known vulnerabilities, RaaS models, and advanced encryption makes attacks more frequent and sophisticated. Organizations must adopt a proactive approach, not only patching but also implementing zero-trust architectures, continuous monitoring, and incident response plans.
International cooperation, as reflected in this advisory, is crucial for sharing intelligence and coordinating actions against these groups. However, the ultimate responsibility lies with each organization to secure its systems and prepare for the worst.