www.darkreading.com 8/11/2026, 10:02:10 PM · external

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
Developing story incident 4 articles tracked
Gentlemen RaaS internal database leak exposes member accounts and chats
CyberSIXT Evidence Panel
Primary Source picussecurity.com
CISA KEV Listed in KEV
Patch Patch Status Unknown
Threat Actor
Gunra

THE Gunra ransomware gang, utilizing known vulnerabilities in Fortinet products, is successfully targeting critical infrastructure and government entities globally. The group employs sophisticated double-extortion tactics and is leveraging leaked source code from the defunct Conti gang. Key vulnerabilities include authentication bypass flaws (CVE-2024-55591 and CVE-2025-24472) that allow attackers to gain super admin access and circumvent multi-factor authentication (MFA).

Gunra's operations extend to a wide range of sectors including healthcare and finance, and they have a structured Ransomware-as-a-Service (RaaS) model that attracts less-skilled cybercriminals. The advisory from U.S. and South Korean government agencies stresses the urgency for organizations to patch these vulnerabilities and implement robust backup strategies to combat ransomware threats.

View Primary Source Via www.darkreading.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline