Connect with us

Security

Fortinet FortiOS and FortiProxy Vulnerabilities Exploited by Gunra Ransomware to Infiltrate Networks

Published

on

Warning Issued by U.S. and South Korea on Gunra Ransomware Attacks Targeting Critical Infrastructure

Cybersecurity and intelligence agencies from South Korea and the U.S. have issued a warning about Gunra ransomware attacks that are targeting critical infrastructure sectors and organizations globally.

The targets of these attacks include healthcare, financial services, government facilities, and professional services.

Chris Butera, the Acting Executive Assistant Director for Cybersecurity at CISA, emphasized that Gunra is part of a trend of ransomware attacks that are causing harm to organizations both in the U.S. and internationally.

These attacks involve exploiting security vulnerabilities in Fortinet FortiOS and FortiProxy appliances to gain initial access, followed by deploying the Gunra ransomware in a double extortion model that involves both data exfiltration and encryption.

Victims who do not pay the ransom within the specified time frame have their data leaked on a public site. The Ransomware.Live platform has listed 51 victims of Gunra since its emergence in April 2025, with most victims located in countries such as South Korea, Brazil, Spain, Thailand, and Hong Kong.

Notably, the majority of targets are in Australia, East Asia, and Europe, with only a few reported cases in Canada and the U.S.

The threat actor behind Gunra utilizes phishing as a primary attack vector to deliver malicious payloads and conducts negotiations through a WhatsApp-themed chat panel. The group is capable of encrypting large amounts of data quickly using advanced encryption techniques.

The group has launched a Ransomware-as-a-Service (RaaS) affiliate program, providing affiliates with tools to distribute the ransomware and earn profits.

Ransomware attack

The FBI reports that Gunra has rebranded itself with new aliases to expand its operations and recruit penetration testers and hackers to gain access to networks for ransom purposes.

See also  Nissan America's Cybersecurity Crisis: Uncovering the Oracle PeopleSoft Data Breach

Attack chains typically use Impacket libraries for lateral movement within networks and credential dumping from compromised servers.

To avoid detection, the group deletes logs and conducts malicious activities during specific hours. Data exfiltration is achieved through various methods, including the use of executable files.

The group has been observed targeting specific regions and industries, with a focus on encrypting critical assets such as database servers and NAS systems.

In some instances, the attackers have manipulated SSL-VPN appliances to intercept credentials and gain access to internal networks.

Gunra’s collaboration with a state-sponsored threat group has led to joint attacks using similar tactics and tools, highlighting the evolving landscape of cyber threats.

To protect against Gunra ransomware, organizations are advised to update systems regularly, patch known vulnerabilities, segment networks, and maintain secure backups.

The collaboration between state-sponsored groups and ransomware actors underscores the need for enhanced cybersecurity measures to combat evolving threats in the digital landscape.

Trending