Fortinet: Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA and Steal Enterprise Data

Fortinet: Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA and Steal Enterprise Data

Gunra Ransomware Group Exploits Fortinet VPN Flaws in Sophisticated Double-Extortion Attacks

A joint cybersecurity advisory from the FBI, CISA, the NSA, the U.S. Secret Service, the Department of Defense Cyber Crime Center, and South Korea’s National Police Agency has revealed a surge in attacks by the Gunra ransomware group, which is actively exploiting Fortinet VPN vulnerabilities to bypass multi-factor authentication (MFA) and exfiltrate sensitive data before encrypting victim networks.

First identified in April 2025, Gunra emerged as a double-extortion ransomware strain built on leaked Conti source code. By early 2026, it evolved into a ransomware-as-a-service (RaaS) operation, offering affiliates a management panel, a customizable ransomware builder, and cross-platform payloads via dark web forums. The group has since rebranded as Golden Community, recruiting penetration testers and ethical hackers as initial access brokers in exchange for a share of ransom profits.

Exploitation of Fortinet VPN Flaws

Gunra affiliates primarily gain access by exploiting known vulnerabilities in Fortinet’s FortiOS and FortiProxy, including:

  • CVE-2024-55591 (authentication bypass)
  • CVE-2025-24472 (authentication bypass)

In one case, attackers compromised an SSL-VPN admin account using default credentials, then modified authentication files to bypass MFA entirely by ensuring a Gunra-designated one-time password would always authenticate successfully.

Post-Exploitation Tactics

Once inside, Gunra operators use Impacket tools (e.g., psexec.py, smbclient.py, secretsdump.py) to move laterally via SMB and extract credentials from domain controllers. Additional tactics include:

  • Session hijacking by stealing VPN session cookies.
  • Decryption of stored passwords using stolen symmetric encryption keys.
  • Data exfiltration via a custom tool (main.exe) targeting Microsoft OneDrive and SharePoint, with stolen files sometimes tens of terabytes transferred to Mega using 7-Zip, RClone, and FileZilla.

The ransomware payload employs ChaCha20 and RSA-4096 encryption, appending the .ENCRT extension to locked files and dropping a ransom note (R3ADM3.txt). Victims are directed to a Tor-based negotiation portal or qTox for payment, with a 5-7 day deadline before stolen data is leaked or sold on Gunra’s dedicated leak site.

Targeted Sectors & Mitigation Recommendations

The advisory highlights healthcare, financial services, critical manufacturing, transportation, and government sectors as primary targets. Organizations are urged to:

  • Patch internet-facing VPN and RDP infrastructure immediately.
  • Maintain offline, immutable backups in segmented locations.
  • Enforce network segmentation to limit lateral movement.
  • Audit VPN and VDI authentication logic for unauthorized modifications.
  • Monitor for Gunra-linked IOCs (IPs, domains, file hashes) published in the CISA advisory.

The group’s ability to bypass MFA and exfiltrate large volumes of data underscores the growing sophistication of ransomware operations.

Source: https://cybersecuritynews.com/gunra-ransomware-exploits-fortinet-vpn-flaws/

Fortinet cybersecurity rating report: https://www.rankiteo.com/company/fortinet

"id": "FOR1786383009",
"linkid": "fortinet",
"type": "Vulnerability",
"date": "4/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Healthcare',
                                     'Financial services',
                                     'Critical manufacturing',
                                     'Transportation',
                                     'Government'],
                        'type': ['Healthcare',
                                 'Financial services',
                                 'Critical manufacturing',
                                 'Transportation',
                                 'Government']}],
 'attack_vector': ['Exploitation of Fortinet VPN vulnerabilities',
                   'Initial access brokers'],
 'data_breach': {'data_encryption': 'ChaCha20 and RSA-4096',
                 'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally identifiable '
                                              'information (PII)',
                                              'Corporate data']},
 'date_detected': '2025-04',
 'description': 'A joint cybersecurity advisory from the FBI, CISA, the NSA, '
                'the U.S. Secret Service, the Department of Defense Cyber '
                'Crime Center, and South Korea’s National Police Agency has '
                'revealed a surge in attacks by the Gunra ransomware group, '
                'which is actively exploiting Fortinet VPN vulnerabilities to '
                'bypass multi-factor authentication (MFA) and exfiltrate '
                'sensitive data before encrypting victim networks. Gunra '
                'operates as a ransomware-as-a-service (RaaS) and has '
                'rebranded as Golden Community, recruiting initial access '
                'brokers. The group uses double-extortion tactics, encrypting '
                'files with ChaCha20 and RSA-4096 and exfiltrating data via '
                'tools like 7-Zip, RClone, and FileZilla.',
 'impact': {'data_compromised': 'Tens of terabytes',
            'identity_theft_risk': 'High (PII exposure)',
            'operational_impact': 'Network encryption, data exfiltration, '
                                  'lateral movement',
            'systems_affected': ['VPN infrastructure',
                                 'Domain controllers',
                                 'Microsoft OneDrive and SharePoint']},
 'initial_access_broker': {'entry_point': ['Fortinet VPN vulnerabilities',
                                           'SSL-VPN admin accounts']},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'The incident highlights the importance of patching '
                    'internet-facing VPN and RDP infrastructure, maintaining '
                    'offline backups, enforcing network segmentation, and '
                    'auditing authentication logic to prevent MFA bypass.',
 'motivation': ['Financial gain', 'Data exfiltration'],
 'post_incident_analysis': {'corrective_actions': ['Patch management',
                                                   'MFA audits',
                                                   'Network segmentation',
                                                   'Enhanced monitoring'],
                            'root_causes': ['Exploitation of unpatched '
                                            'Fortinet VPN vulnerabilities',
                                            'MFA bypass via authentication '
                                            'file modification']},
 'ransomware': {'data_encryption': True,
                'data_exfiltration': True,
                'ransomware_strain': 'Gunra (based on Conti source code)'},
 'recommendations': ['Patch internet-facing VPN and RDP infrastructure '
                     'immediately.',
                     'Maintain offline, immutable backups in segmented '
                     'locations.',
                     'Enforce network segmentation to limit lateral movement.',
                     'Audit VPN and VDI authentication logic for unauthorized '
                     'modifications.',
                     'Monitor for Gunra-linked IOCs (IPs, domains, file '
                     'hashes).'],
 'references': [{'source': 'Joint cybersecurity advisory (FBI, CISA, NSA, U.S. '
                           'Secret Service, DoD Cyber Crime Center, South '
                           'Korea’s National Police Agency)'}],
 'response': {'containment_measures': ['Network segmentation',
                                       'Monitoring for IOCs'],
              'enhanced_monitoring': 'Recommended',
              'law_enforcement_notified': 'FBI, CISA, NSA, U.S. Secret '
                                          'Service, DoD Cyber Crime Center, '
                                          'South Korea’s National Police '
                                          'Agency',
              'network_segmentation': 'Recommended',
              'recovery_measures': ['Offline, immutable backups'],
              'remediation_measures': ['Patching Fortinet VPN vulnerabilities',
                                       'Enforcing MFA audits']},
 'stakeholder_advisories': 'Organizations in healthcare, financial services, '
                           'critical manufacturing, transportation, and '
                           'government sectors are urged to follow mitigation '
                           'recommendations.',
 'threat_actor': 'Gunra (Golden Community)',
 'title': 'Gunra Ransomware Group Exploits Fortinet VPN Flaws in Sophisticated '
          'Double-Extortion Attacks',
 'type': 'Ransomware',
 'vulnerability_exploited': ['CVE-2024-55591', 'CVE-2025-24472']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.