Skip to content
Threat Feed
high threat

Gunra Ransomware Gang Exploitation of Fortinet Appliances

The Gunra ransomware-as-a-service group is leveraging critical Fortinet vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to gain initial access, hijack VDI sessions, and bypass multi-factor authentication in attacks against critical infrastructure.

CVE search metadata

CVE search record: CVE-2024-55591. Severity: critical. CVSS: 9.8. EPSS: 98.26%. KEV: no. Product: FortiOS, FortiProxy. Brief: Gunra Ransomware Gang Exploitation of Fortinet Appliances. Brief link: https://feed.craftedsignal.io/briefs/2026-08-gunra-ransomware/

CVE search record: CVE-2025-24472. Severity: high. CVSS: 8.1. EPSS: 3.87%. KEV: no. Product: FortiOS, FortiProxy. Brief: Gunra Ransomware Gang Exploitation of Fortinet Appliances. Brief link: https://feed.craftedsignal.io/briefs/2026-08-gunra-ransomware/

The Gunra ransomware-as-a-service (RaaS) operation has emerged as a significant threat to global critical infrastructure, including healthcare, financial services, and government sectors. First observed in spring 2025, the group utilizes leaked Conti source code to conduct double-extortion attacks. Since early 2026, Gunra has expanded through an affiliate program, attracting less-sophisticated actors by providing user-friendly management panels and customizable ransomware builders. Gunra is notably characterized by its focus on identity and access management (IAM) infrastructure, frequently conducting credential dumping, session hijacking, and the manipulation of authentication files on VDI portals to circumvent multifactor authentication (MFA). Recent reporting by a joint multi-agency coalition identifies the group's use of N-day vulnerabilities in Fortinet appliances for initial access, specifically CVE-2024-55591 and CVE-2025-24472.

Attack Chain

  1. Attackers identify internet-facing Fortinet VPN or firewall appliances vulnerable to CVE-2024-55591 or CVE-2025-24472.
  2. The threat actors exploit the authentication bypass vulnerabilities to gain administrative access to the network appliance.
  3. Attackers leverage the appliance's traffic control functionality to intercept credentials and session cookies from users accessing the corporate virtual desktop infrastructure (VDI).
  4. Stolen session cookies are used to hijack legitimate VDI sessions, effectively bypassing MFA requirements.
  5. The actors gain persistence and deeper access by modifying authentication processing files on the VDI gateway to accept attacker-designated OTP values.
  6. Attackers conduct lateral movement and credential dumping, including harvesting keys from access control servers and dumping memory on compromised hosts.
  7. The group identifies and deletes primary and disaster recovery backups to prevent restoration.
  8. Final objective is reached via the deployment of Gunra ransomware to encrypt target files, followed by data exfiltration for double extortion.

Impact

Gunra has successfully targeted organizations across North and South America, Europe, the Middle East, Africa, and the Asia-Pacific region, with notable concentrations of activity in Brazil and South Korea. Successful compromises result in catastrophic operational disruption, loss of critical data via encryption, and exposure of sensitive information. The group's ability to delete offsite backups and manipulate identity verification mechanisms significantly elevates the recovery time and security risk for affected entities.

Recommendation

  • Patch CVE-2024-55591 and CVE-2025-24472 on all internet-facing Fortinet VPN and firewall appliances immediately.
  • Implement offline, immutable backups for primary and disaster recovery data centers to prevent total data loss during a ransomware event.
  • Monitor authentication logs and file integrity for critical identity and access management servers, including VDI portals, for unauthorized modifications.
  • Enforce strict network segmentation to limit the reach of attackers who achieve initial access via perimeter appliances.

Immediate actions

Patch CVE-2024-55591 and CVE-2025-24472 on all FortiOS and FortiProxy appliances.

IT Operations 24h

Mitigations

Review VDI portal authentication configurations for unauthorized file modifications.

immediate SOC

MFA bypass technique