<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Gunra - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/actors/gunra/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 11 Aug 2026 11:28:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/actors/gunra/feed.xml" rel="self" type="application/rss+xml"/><item><title>Gunra Ransomware Exploitation of Fortinet and Schneider Electric Vulnerabilities</title><link>https://feed.craftedsignal.io/briefs/2026-08-gunra-ransomware/</link><pubDate>Tue, 11 Aug 2026 11:28:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-gunra-ransomware/</guid><description>The Gunra ransomware group is leveraging CVE-2024-5559 and CVE-2025-24472 to gain initial access and execute a double-extortion campaign against global critical infrastructure.</description><content:encoded><![CDATA[<p>Gunra is a ransomware operation that has evolved since April 2025 to target critical infrastructure sectors globally, including government, finance, and healthcare. The group operates a Ransomware-as-a-Service (RaaS) model and is known for double extortion, combining data exfiltration with encryption. Recent activity involves the exploitation of internet-facing vulnerabilities in Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS/FortiProxy (CVE-2025-24472) to obtain initial network access.</p>
<p>The group demonstrates high technical proficiency, including manipulating VDI and SSL-VPN authentication flows to bypass MFA and harvesting sensitive configuration data from enterprise environments. They use a mix of native tools, Impacket libraries, and custom payloads to facilitate lateral movement, credential dumping, and mass exfiltration of business data. Despite a identified cryptographic weakness in Linux variants, the group remains a significant threat due to their aggressive recruiting of initial access brokers and ability to deploy ransomware rapidly against database servers and NAS systems.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial access is established by exploiting known vulnerabilities (CVE-2024-5559 or CVE-2025-24472) in internet-facing Schneider Electric or Fortinet appliances.</li>
<li>Attackers gain administrative access to SSL-VPN or VDI portals, often by manipulating authentication files to enable bypasses or using default credentials.</li>
<li>Persistent access is maintained by downloading OpenSSH and configuring backdoors on compromised appliances.</li>
<li>Internal reconnaissance is conducted using compromised credentials to identify domain controllers and enterprise server infrastructure.</li>
<li>Lateral movement is performed using Impacket tools such as psexec.py and smbclient.py, while secretsdump.py is utilized to extract credentials from NTDS files.</li>
<li>Data is exfiltrated from Microsoft OneDrive, SharePoint, and VDI environments using a custom executable named 'main.exe' or via large compressed archives to MEGA.</li>
<li>Backup and recovery infrastructure is identified and systematically deleted to prevent restoration.</li>
<li>Final objective is achieved by deploying ransomware payloads to encrypt database servers, NAS systems, and critical enterprise assets.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Gunra has successfully targeted at least 51 victims across South Korea, Brazil, Spain, Thailand, and Hong Kong since April 2025. The attack impacts critical sectors by causing severe operational disruption and potential long-term data loss through unauthorized disclosure. Organizations that refuse to pay the ransom face the permanent leakage of sensitive business data on public forums, impacting regulatory compliance and reputation.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch CVE-2024-5559 on all internet-facing Schneider Electric PowerLogic P5 devices immediately.</li>
<li>Patch CVE-2025-24472 on all Fortinet FortiOS and FortiProxy appliances to prevent initial exploitation.</li>
<li>Implement strict network segmentation and monitor for unauthorized lateral movement involving Impacket tools and SMB traffic.</li>
<li>Audit VDI and SSL-VPN authentication portals for modified configuration files or anomalous MFA bypass logic.</li>
<li>Deploy immutable, off-site backups to ensure business continuity following potential ransomware deployment.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item></channel></rss>