Cybersecurity authorities from the US and South Korea have issued a warning about the Gunra ransomware group exploiting vulnerabilities in Fortinet products to target critical infrastructure and government entities. Gunra, a ransomware-as-a-service operation, takes advantage of known security weaknesses in internet-facing devices such as firewalls and VPNs to gain unauthorized access. Once inside, the actors employ sophisticated techniques to maintain access and move laterally within networks, enabling them to exfiltrate substantial amounts of data, primarily from Microsoft 365 services.
The advisory, authored by the FBI, CISA, and South Korea’s National Police Agency, highlights that Gunra's tactics include exploiting two specific Fortinet vulnerabilities related to authentication bypass in certain FortiOS and FortiProxy versions. Although patches are available, the report stresses that fixing these vulnerabilities does not address backdoors that may already exist. Gunra has been observed bypassing multi-factor authentication by altering processing files on corporate servers, demonstrating their advanced persistence capabilities.
The group, also known as Golden Community, operates mainly during nighttime hours when network monitoring is typically reduced, allowing them to avoid detection. They meticulously avoid encrypting non-essential files, focusing instead on user-specific data, which they exfiltrate using tools like OpenSSH and malicious executables. In some instances, they have extracted up to tens of terabytes of data to file-sharing platforms like Mega.
Ransom demands often start in the tens of millions, and victims have a short window to negotiate, typically through a Tor-based portal. Failure to comply results in threats of data exposure on Gunra's leak site. The group has targeted a variety of sectors, including healthcare, financial services, government, and critical manufacturing, across multiple regions.


