{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/actors/gunra/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":["Gunra"],"_cs_cpes":["cpe:2.3:o:schneider-electric:powerlogic_p5_firmware:*:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.1,"id":"CVE-2024-5559"},{"cvss":8.1,"id":"CVE-2025-24472"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PowerLogic P5","FortiOS","FortiProxy","AnySign4PC"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Schneider Electric","Fortinet","AnySign4PC"],"content_html":"\u003cp\u003eGunra is a ransomware operation that has evolved since April 2025 to target critical infrastructure sectors globally, including government, finance, and healthcare. The group operates a Ransomware-as-a-Service (RaaS) model and is known for double extortion, combining data exfiltration with encryption. Recent activity involves the exploitation of internet-facing vulnerabilities in Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS/FortiProxy (CVE-2025-24472) to obtain initial network access.\u003c/p\u003e\n\u003cp\u003eThe group demonstrates high technical proficiency, including manipulating VDI and SSL-VPN authentication flows to bypass MFA and harvesting sensitive configuration data from enterprise environments. They use a mix of native tools, Impacket libraries, and custom payloads to facilitate lateral movement, credential dumping, and mass exfiltration of business data. Despite a identified cryptographic weakness in Linux variants, the group remains a significant threat due to their aggressive recruiting of initial access brokers and ability to deploy ransomware rapidly against database servers and NAS systems.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is established by exploiting known vulnerabilities (CVE-2024-5559 or CVE-2025-24472) in internet-facing Schneider Electric or Fortinet appliances.\u003c/li\u003e\n\u003cli\u003eAttackers gain administrative access to SSL-VPN or VDI portals, often by manipulating authentication files to enable bypasses or using default credentials.\u003c/li\u003e\n\u003cli\u003ePersistent access is maintained by downloading OpenSSH and configuring backdoors on compromised appliances.\u003c/li\u003e\n\u003cli\u003eInternal reconnaissance is conducted using compromised credentials to identify domain controllers and enterprise server infrastructure.\u003c/li\u003e\n\u003cli\u003eLateral movement is performed using Impacket tools such as psexec.py and smbclient.py, while secretsdump.py is utilized to extract credentials from NTDS files.\u003c/li\u003e\n\u003cli\u003eData is exfiltrated from Microsoft OneDrive, SharePoint, and VDI environments using a custom executable named 'main.exe' or via large compressed archives to MEGA.\u003c/li\u003e\n\u003cli\u003eBackup and recovery infrastructure is identified and systematically deleted to prevent restoration.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved by deploying ransomware payloads to encrypt database servers, NAS systems, and critical enterprise assets.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eGunra has successfully targeted at least 51 victims across South Korea, Brazil, Spain, Thailand, and Hong Kong since April 2025. The attack impacts critical sectors by causing severe operational disruption and potential long-term data loss through unauthorized disclosure. Organizations that refuse to pay the ransom face the permanent leakage of sensitive business data on public forums, impacting regulatory compliance and reputation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2024-5559 on all internet-facing Schneider Electric PowerLogic P5 devices immediately.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2025-24472 on all Fortinet FortiOS and FortiProxy appliances to prevent initial exploitation.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation and monitor for unauthorized lateral movement involving Impacket tools and SMB traffic.\u003c/li\u003e\n\u003cli\u003eAudit VDI and SSL-VPN authentication portals for modified configuration files or anomalous MFA bypass logic.\u003c/li\u003e\n\u003cli\u003eDeploy immutable, off-site backups to ensure business continuity following potential ransomware deployment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T11:28:56Z","date_published":"2026-08-11T11:28:56Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gunra-ransomware/","summary":"The Gunra ransomware group is leveraging CVE-2024-5559 and CVE-2025-24472 to gain initial access and execute a double-extortion campaign against global critical infrastructure.","title":"Gunra Ransomware Exploitation of Fortinet and Schneider Electric Vulnerabilities","url":"https://feed.craftedsignal.io/briefs/2026-08-gunra-ransomware/"}],"language":"en","title":"CraftedSignal Threat Feed - Gunra","version":"https://jsonfeed.org/version/1.1"}