GUNRA ransomware is exploiting two vulnerabilities in Fortinet products to target critical infrastructure and government entities, as highlighted in a joint advisory from US and South Korean agencies. This ransomware-as-a-service (RaaS) is capable of advanced lateral movement and data exfiltration, particularly from Microsoft 365 services. Gunra utilizes stealth tactics to remain undetected, often conducting malicious activities during off-hours.
It demands ransoms in the tens of millions and employs a double-extortion strategy, threatening to leak data. Organizations are advised to patch vulnerabilities, implement secure backups, and segment networks to mitigate risks.