A joint cybersecurity advisory from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s National Police Agency has exposed a dangerous new wave of attacks by the Gunra ransomware group, which is actively exploiting known Fortinet VPN vulnerabilities to bypass multi-factor authentication and exfiltrate sensitive enterprise data before locking down victim networks.
Gunra first surfaced in April 2025 as a double-extortion ransomware strain believed to be built on leaked Conti source code. By early 2026, the group had matured into a full ransomware-as-a-service operation, offering affiliates a management panel, a configurable ransomware builder, and cross-platform locker payloads through dark web forums.
The FBI also observed the group rebranding under the alias Golden Community while actively recruiting penetration testers and ethical hackers as initial access brokers in exchange for a cut of ransom profits.
Gunra Ransomware Exploits Fortinet VPN Flaws
Investigators confirmed that Gunra affiliates gain initial access primarily by exploiting known vulnerabilities in internet-facing VPN and firewall appliances, most notably CVE-2024-55591 and CVE-2025-24472, both authentication bypass flaws affecting specific FortiOS and FortiProxy versions.
In one documented case, actors compromised an SSL-VPN administrator account protected by default credentials with no lockout controls, then modified authentication files on a corporate VDI portal so that a Gunra-designated one-time password value would always authenticate successfully, effectively neutralizing MFA protections entirely.
Once inside, Gunra operators lean heavily on Impacket tools such as psexec.py, smbclient.py, and secretsdump.py to move across networks via SMB and dump credentials from domain controllers, enabling pass-the-hash and pass-the-ticket attacks.
The group has also intercepted VPN traffic to steal session cookies for hijacking legitimate user sessions and, in at least one case, stole a symmetric encryption key from a system access control server to decrypt stored enterprise passwords en masse.
True to its double-extortion model, Gunra exfiltrates data before deploying its encryptor. Actors have used a custom tool named main.exe to siphon files from Microsoft OneDrive and SharePoint, and have moved compressed archives, sometimes totaling tens of terabytes, to the file-sharing platform Mega. Open-source utilities including 7-Zip, RClone, and FileZilla support this collection and transfer process.
The final payload uses ChaCha20 and RSA-4096 encryption across a multi-threaded architecture, appending the .ENCRT extension to locked files and dropping a ransom note, R3ADM3.txt, in every affected directory.
Victims are pushed toward a Tor-based negotiation portal or the encrypted messaging app qTox, typically given five to seven days before Gunra threatens to leak or sell stolen data on its dedicated leak site.
The advisory urges organizations, especially in healthcare, financial services, critical manufacturing, transportation, and government sectors, to prioritize patching internet-facing VPN and RDP infrastructure, maintain offline and immutable backups in segmented locations, and enforce network segmentation to contain lateral movement.
Given Gunra’s demonstrated ability to bypass MFA through authentication file tampering, security teams should also audit VPN and VDI authentication logic for unauthorized modifications and monitor for known Gunra-linked IP addresses, domains, and file hashes published in the CISA advisory’s indicators of compromise.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA and Steal Enterprise Data appeared first on Cyber Security News.


