security
Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data
US cyber agencies are warning critical infrastructure operators to patch their internet-facing kit after Gunra ransomware affiliates were spotted exploiting known vulnerabilities to break into networks.
Gunra first surfaced in 2025 and has wasted little time expanding. CISA, the FBI, NSA, Secret Service, and partner agencies in the US and South Korea say it now operates as ransomware-as-a-service, with affiliates attacking organizations worldwide.
Targets have included healthcare, financial services, government, professional services, nonprofits, and other critical infrastructure organizations.
The attackers have exploited CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in Fortinet's FortiOS and FortiProxy, to gain administrative access through internet-facing appliances.
Once inside, Gunra affiliates follow the now-familiar double-extortion playbook: steal data, encrypt systems, and demand payment for a decryptor and a promise not to publish the haul.
Negotiations take place through a Tor-based portal, according to the advisory, with victims typically given between five and seven days to cough up before their stolen data is published.
"Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to US and international organizations," said Chris Butera, CISA's acting executive assistant director for cybersecurity.
Trend Micro first observed Gunra in April 2025, initially targeting Windows systems and borrowing elements from the Conti ransomware operation. The security shop later uncovered a Linux variant, broadening the range of systems its operators could scramble.
That Linux version can run as many as 100 encryption threads in parallel and supports partial encryption, allowing attackers to specify how much of individual files should be encrypted. It can also store RSA-encrypted keys in separate keystore files.
Trend Micro has seen Gunra activity in Turkey, Taiwan, the US, and South Korea. The gang's own leak site casts the net wider, claiming victims in Brazil, Japan, and Canada as well, including manufacturers, healthcare providers, IT companies, and law firms.
The agencies are urging potential targets to patch known exploited vulnerabilities in internet-facing systems, secure VPN gateways and RDP access with multifactor authentication, segment networks, and maintain offline, immutable backups to make life harder for attackers who get through the front door. ®

3 hours ago
10







English (US) ·