VMTech
Discuss a project

Gunra ransomware uses Fortinet and Schneider Electric flaws for access

Gunra ransomware uses Fortinet and Schneider Electric flaws for access

Cybersecurity agencies in the United States and South Korea have warned that Gunra ransomware operators are exploiting internet-facing Schneider Electric PowerLogic P5 and Fortinet FortiOS and FortiProxy vulnerabilities to gain initial access to enterprise networks. The flaws cited are CVE-2024-5559 in PowerLogic P5 and CVE-2025-24472 in Fortinet appliances.

The attacks target critical infrastructure and organisations worldwide, including healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. Gunra combines data exfiltration with encryption in a double-extortion model, giving victims five to seven days to pay before publishing stolen information on a leak site.

A ransomware operation with expanding reach

Ransomware.Live data shows Gunra has listed 51 victims since it emerged in April 2025. Most listed victims are in South Korea, Brazil, Spain, Thailand and Hong Kong, while the majority of targets are in Australia, East Asia and Europe. Only three victims have been reported in Canada and the United States.

Gunra is described as a Conti-derived operation. In January 2026, it launched a formal ransomware-as-a-service affiliate programme with a management panel, configurable ransomware builder, cross-platform locker payloads and affiliate documentation. The group provides Windows and Linux variants, although Breakglass Intelligence identified a cryptographic weakness in Linux builds in March 2026 that could allow recovery of the encryption key.

The FBI said the group has adopted aliases including Golden Community and has sought to recruit penetration testers and ethical hackers as initial access brokers in return for a share of ransom proceeds. This reflects the broader pressure on exposed enterprise infrastructure also examined in vulnerabilities and familiar administrative tools, where vulnerabilities and familiar administrative tools can become entry points for attackers.

Credential theft, lateral movement and destructive actions

Investigators observed the use of Impacket tools including psexec.py and smbclient.py for SMB-based lateral movement. The secretsdump.py utility was used against compromised domain controllers to extract user password hashes from the NT Directory Services file. Operators also delete system and network access logs and clear command histories, often conducting reconnaissance and other activity between 10 p.m. and 6 a.m.

Gunra has exfiltrated Microsoft OneDrive and SharePoint data using an executable named main.exe. In some incidents, the attackers created compressed archives containing terabytes of data and transferred them to MEGA. They also accessed IT staff virtual desktop infrastructure environments to obtain documents containing system and network configuration information.

CISA described cases in which stolen enterprise server credentials were used to deploy ransomware against database servers and network-attached storage systems. South Korea's National Police Agency also observed manipulation of SSL-VPN traffic controls to capture credentials and session information from users authenticating to a corporate VDI portal. Stolen cookies enabled session hijacking, while tampering with authentication processing files allowed a Gunra-designated one-time password to bypass MFA.

Defensive priorities

The agencies advise organisations to keep operating systems, software and firmware current, with priority given to known exploited flaws in internet-facing systems. Network segmentation, hardened VPN and VDI administration, and monitoring for credential theft and abnormal SMB activity are relevant controls in the attack paths described.

Gunra actors have also deleted backup and archived data at both primary data centres and disaster-recovery sites. For business leaders, the practical implication is to prioritise rapid patching of exposed appliances and verify that backups are immutable, physically separate and recoverable when an attacker has obtained administrative credentials.

#ransomware#cybersecurity#fortinet#threatintel
Open analytics
On the site 0 views
min read 4 12.08.2026
Instagram

Gunra ransomware uses Fortinet and Schneider Electric flaws for access

Open the post on Instagram ↗