Schneider Electric and Fortinet: Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass

Schneider Electric and Fortinet: Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass

U.S. and South Korea Warn of Evolving Gunra Ransomware Threats to Critical Infrastructure

U.S. and South Korean intelligence agencies have issued a joint advisory warning of Gunra ransomware attacks targeting global critical infrastructure, including healthcare, financial services, government, and industrial sectors. The group has advanced from sporadic encryption attacks to sophisticated exploitation of IT and operational technology (OT) environments, leveraging legacy vulnerabilities in Fortinet and Schneider Electric systems alongside a previously undocumented MFA bypass technique.

Exploitation of Fortinet and Schneider Electric for Initial Access

Gunra, which builds its ransomware on leaked Conti code, gains entry by exploiting unpatched Fortinet firewalls and VPNs including SonicWall SMA1000 flaws to establish administrative access. From there, attackers pivot to Schneider Electric industrial controllers, bridging IT and OT networks. This dual-vector approach allows lateral movement across corporate systems while compromising physical infrastructure controls, such as power, water, and heating systems, posing severe operational risks.

MFA Bypass via Device Code Phishing

After breaching networks, Gunra bypasses multi-factor authentication (MFA) using a device code phishing technique targeting Microsoft 365 and other cloud identity providers. Attackers register malicious applications, trigger device code challenges, and relay authentication tokens to obtain valid sessions without user interaction. This method evades detection, as the resulting sessions appear legitimate in cloud logs. Intelligence agencies emphasize the need for auditing Microsoft 365 logs and enforcing conditional access policies to block suspicious device registrations.

DeadLock Ransomware’s Shift to Blockchain-Based Extortion

In a separate development, Microsoft Threat Intelligence reported that DeadLock ransomware has adopted decentralized infrastructure, using Polygon blockchain smart contracts, Session messenger, and encrypted cloud storage for victim communications and data leaks. Unlike traditional ransomware, DeadLock’s on-chain operations make takedowns nearly impossible, as its infrastructure exists across decentralized protocols rather than centralized servers. This evolution forces law enforcement to shift from server seizures to blockchain tracing, complicating disruption efforts.

Key Takeaways on Ransomware Evolution

The advisories highlight two major shifts in ransomware tactics:

  • Gunra’s MFA bypass and IT/OT exploitation demonstrate an expansion into critical infrastructure, requiring organizations to patch Fortinet and Schneider systems and monitor for device code phishing artifacts.
  • DeadLock’s blockchain-based extortion marks a fundamental change in ransomware resilience, as decentralized infrastructure renders traditional takedown methods ineffective.

Both groups continue to refine their operations, underscoring the need for proactive defense strategies as conventional disruption tactics lose effectiveness.

Source: https://dailysecurityreview.com/ransomware/gunra-ransomware-exploits-fortinet-and-schneider-flaws-for-mfa-bypass/

Schneider Electric TPRM report: https://www.rankiteo.com/company/schneider-electric

Fortinet TPRM report: https://www.rankiteo.com/company/fortinet

"id": "schfor1786559183",
"linkid": "schneider-electric, fortinet",
"type": "Vulnerability",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['healthcare',
                                     'financial services',
                                     'government',
                                     'industrial'],
                        'location': 'global',
                        'type': ['healthcare',
                                 'financial services',
                                 'government',
                                 'industrial']}],
 'attack_vector': ['exploitation of unpatched vulnerabilities',
                   'MFA bypass via device code phishing'],
 'data_breach': {'data_encryption': 'data encryption by ransomware'},
 'description': 'U.S. and South Korean intelligence agencies have issued a '
                'joint advisory warning of Gunra ransomware attacks targeting '
                'global critical infrastructure, including healthcare, '
                'financial services, government, and industrial sectors. The '
                'group has advanced from sporadic encryption attacks to '
                'sophisticated exploitation of IT and operational technology '
                '(OT) environments, leveraging legacy vulnerabilities in '
                'Fortinet and Schneider Electric systems alongside a '
                'previously undocumented MFA bypass technique.',
 'impact': {'operational_impact': 'severe operational risks to critical '
                                  'infrastructure',
            'systems_affected': ['IT networks',
                                 'OT networks',
                                 'power systems',
                                 'water systems',
                                 'heating systems']},
 'initial_access_broker': {'entry_point': ['Fortinet firewalls and VPNs',
                                           'SonicWall SMA1000 flaws'],
                           'high_value_targets': ['IT networks',
                                                  'OT networks']},
 'lessons_learned': 'Gunra’s MFA bypass and IT/OT exploitation demonstrate an '
                    'expansion into critical infrastructure, requiring '
                    'organizations to patch Fortinet and Schneider systems and '
                    'monitor for device code phishing artifacts. DeadLock’s '
                    'blockchain-based extortion marks a fundamental change in '
                    'ransomware resilience, as decentralized infrastructure '
                    'renders traditional takedown methods ineffective.',
 'motivation': ['financial gain', 'disruption of critical infrastructure'],
 'post_incident_analysis': {'corrective_actions': ['patch management',
                                                   'enhanced monitoring',
                                                   'conditional access '
                                                   'policies'],
                            'root_causes': ['unpatched vulnerabilities',
                                            'MFA bypass via device code '
                                            'phishing']},
 'ransomware': {'data_encryption': True,
                'ransomware_strain': ['Gunra', 'DeadLock']},
 'recommendations': ['Patch Fortinet and Schneider Electric systems',
                     'Monitor for device code phishing artifacts',
                     'Audit Microsoft 365 logs',
                     'Enforce conditional access policies',
                     'Adopt proactive defense strategies'],
 'references': [{'source': 'U.S. and South Korean intelligence agencies'},
                {'source': 'Microsoft Threat Intelligence'}],
 'response': {'enhanced_monitoring': ['auditing Microsoft 365 logs',
                                      'enforcing conditional access policies']},
 'threat_actor': ['Gunra', 'DeadLock'],
 'title': 'U.S. and South Korea Warn of Evolving Gunra Ransomware Threats to '
          'Critical Infrastructure',
 'type': ['ransomware', 'cyberattack'],
 'vulnerability_exploited': ['Fortinet firewalls and VPNs',
                             'SonicWall SMA1000 flaws',
                             'Schneider Electric industrial controllers']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.