Connect with us

Security

Cybersecurity Alert: Gunra Ransomware Strikes Through Fortinet and Schneider Electric Vulnerabilities

Published

on

Cybersecurity Warning: Gunra Ransomware Targets Critical Infrastructure Worldwide

A joint alert from cybersecurity and intelligence agencies in South Korea and the U.S. has highlighted the threat posed by Gunra ransomware targeting critical infrastructure sectors and organizations globally.

Various sectors, including healthcare, financial services, government facilities, and nonprofit organizations, have fallen victim to these attacks.

According to Chris Butera, Acting Executive Assistant Director for Cybersecurity at CISA, Gunra represents a new wave of ransomware attacks that are causing significant disruption and harm to organizations both in the U.S. and internationally.

Reports indicate that the ransomware is being deployed by exploiting security vulnerabilities in Schneider Electric PowerLogic P5 and Fortinet FortiOS and FortiProxy appliances to gain initial access. Subsequently, the attackers utilize a double extortion model, combining data exfiltration and encryption, to maximize their impact.

Victims who do not meet the ransom demands within a specified time frame face the threat of having their data leaked. Ransomware.Live data reveals that Gunra has targeted 51 victims since its emergence in April 2025, with a concentration in countries such as South Korea, Brazil, Spain, Thailand, and Hong Kong.

Notably, the majority of targets are located in Australia, East Asia, and Europe, with limited instances reported in Canada and the U.S.

Security researcher Rakesh Krishnan’s analysis indicates that the threat actors primarily use phishing techniques to deliver malicious payloads and conduct negotiations through a WhatsApp-themed chat panel. The group showcases the capability to encrypt large volumes of data quickly using advanced encryption techniques like Salsa20 or ChaCha20.

Ransomware-as-a-Service (RaaS) Operations

The operation, derived from Conti ransomware, launched a formal RaaS affiliate program on dark web forums in January 2026. Affiliates are provided access to a management panel, a ransomware builder, cross-platform locker payloads, and detailed affiliate documentation.

See also  Cybersecurity First: How to Embed Data Protection in Your Startup's DNA from the Start

While both Windows and Linux variants of the locker are offered, a cryptographic weakness was identified in the Linux builds, allowing for the recovery of encryption keys and file access.

Ransomware attack

Evolution of Gunra Ransomware

The FBI notes that Gunra has adopted new branding aliases like Golden Community to expand its operations. The group is also recruiting penetration testers and ethical hackers as initial access brokers, offering them a share of ransom profits in exchange for network access.

Attack chains involve using Impacket libraries for lateral movement via the SMB protocol and conducting credential dumping against compromised domain controllers to extract password hashes.

To cover their tracks, the threat actors delete logs, clear command history, and conduct malicious activities during specific hours. Data exfiltration is achieved through an executable named “main.exe” to services like Microsoft OneDrive and SharePoint.

In some cases, the group has exfiltrated terabytes of data to the MEGA file-sharing service, targeting sensitive documents and network configuration information within IT personnel’s virtual desktop infrastructure (VDI) environments.

According to CISA, Gunra actors have used stolen enterprise server credentials to deploy ransomware, encrypting critical assets such as database servers and NAS systems.

An incident reported by South Korea’s National Police Agency revealed attackers exploiting SSL-VPN appliance functionalities to intercept credentials and gain internal network access through session hijacking.

Gunra has been known to manipulate authentication files on VDI servers to bypass multi-factor authentication and gain unauthorized access.

Other observed behaviors include exploiting default credentials on SSL-VPN appliances, modifying configuration settings to maintain persistence, and deleting backup data before and after ransomware deployment.

See also  Stealthy Cyber Threat: Unveiling the Malicious MoltBot's Password-Stealing Tactics

Collaboration and Commonalities

Recent advisories from South Korea highlight a cyber campaign by an unspecified state-sponsored group exploiting vulnerabilities to distribute malware. Some incidents also involve leveraging these vulnerabilities to deploy Gunra ransomware.

ENKI reports watering hole attacks exploiting zero-day vulnerabilities in AnySign4PC, distributing payloads associated with Lazarus Group tools like Struggle and Brandoor.

While the state-sponsored group and Gunra ransomware actors seem distinct, shared techniques and infrastructure suggest potential collaboration. Past instances indicate partnerships between nation-state groups and ransomware actors, underscoring the need for heightened cybersecurity measures.

Mitigation Strategies

Organizations are advised to maintain updated systems, patch known vulnerabilities, enforce network segmentation, and ensure secure backups stored in separate locations to mitigate Gunra ransomware risks.

Trending