THE Gunra ransomware gang, utilizing known vulnerabilities in Fortinet products, is successfully targeting critical infrastructure and government entities globally. The group employs sophisticated double-extortion tactics and is leveraging leaked source code from the defunct Conti gang. Key vulnerabilities include authentication bypass flaws (CVE-2024-55591 and CVE-2025-24472) that allow attackers to gain super admin access and circumvent multi-factor authentication (MFA).
Gunra's operations extend to a wide range of sectors including healthcare and finance, and they have a structured Ransomware-as-a-Service (RaaS) model that attracts less-skilled cybercriminals. The advisory from U.S. and South Korean government agencies stresses the urgency for organizations to patch these vulnerabilities and implement robust backup strategies to combat ransomware threats.