Gunra ransomware is rapidly becoming a significant enterprise threat, exploiting Fortinet vulnerabilities to steal remote sessions and pivot via RDP into Active Directory and IT workstations. The operation’s technical sophistication and double extortion tactics pose acute risks to organisations using FortiOS and FortiProxy devices.
Gunra Ransomware: Exploiting Fortinet Devices for Initial Access
First observed in April 2025, Gunra is a ransomware-as-a-service (RaaS) group derived from leaked Conti source code. It targets both Windows and Linux environments and has been linked to attacks on government, critical infrastructure, healthcare and private sectors globally. Gunra’s affiliates are known for breaching organisations by exploiting authentication bypass vulnerabilities in Fortinet FortiOS and FortiProxy devices, specifically CVE-2024-55591 and CVE-2025-24472.
These vulnerabilities allow remote, unauthenticated attackers to gain super admin privileges on affected Fortinet appliances. CVE-2024-55591 enables attackers to use crafted requests targeting the Node.js websocket module. CVE-2025-24472, disclosed in February 2025, impacts deployments with Security Fabric enabled, allowing super admin access with knowledge of specific device serial numbers. Both vulnerabilities have seen active exploitation in the wild, with CVE-2024-55591 observed as a zero day from at least November 2024.
Attack Chain: Session Theft and RDP Lateral Movement
Gunra affiliates’ attacks begin with the compromise of internet-facing Fortinet appliances. Once access is gained, they create persistent superuser accounts and manipulate the device’s remote access features. This enables them to collect credentials and active session data from users authenticating to virtual desktop portals.
Stolen sessions are then reused to enter internal virtual desktop infrastructure (VDI) environments. From there, attackers pivot laterally using Remote Desktop Protocol (RDP), targeting:
- VDI authentication web servers
- Active Directory domain controllers
- IT administration workstations
Before detonating ransomware, Gunra operators exfiltrate large volumes of sensitive data, including documents, databases and email. The ransomware payload uses a multithreaded ChaCha20 encryption scheme with RSA-protected keys, appending .ENCRT to affected files. Victims face double extortion: not only are files encrypted, but there is also the threat that stolen data will be published or sold if the ransom is not paid.
Technical Details of Fortinet Vulnerabilities
- CVE-2024-55591: Impacts FortiOS 7.0.0–7.0.16 (fixed in 7.0.17) and FortiProxy 7.0.0–7.0.19, 7.2.0–7.2.12. Enables authentication bypass via crafted websocket requests.
- CVE-2025-24472: Impacts FortiOS and FortiProxy in the same version ranges when Security Fabric is enabled. Attackers can use knowledge of device serials to send CSF proxy requests and gain admin access.
Fortinet released patches for CVE-2024-55591 in January 2025 and for CVE-2025-24472 in February 2025. Despite this, active exploitation has continued, particularly targeting organisations slow to upgrade or with exposed edge devices.
Event Timeline and Exploitation Status
- 14 January 2025: Fortinet discloses and patches CVE-2024-55591 after observing in-the-wild attacks.
- February 2025: CVE-2025-24472 disclosed and patched.
- April 2025: Gunra activity detected in Windows environments.
- Mid 2025: Linux variant emerges.
- January 2026: Gunra RaaS affiliate programme launched.
- 10 August 2026: US and South Korea issue a joint advisory detailing Gunra’s exploitation of Fortinet flaws and RDP pivoting.
Government and industry reporting confirms that both vulnerabilities have been, and continue to be, actively exploited. Gunra affiliates have targeted a wide range of sectors worldwide, with the NHS National CSOC warning of ongoing exploitation and high risk to UK organisations.
Indicators of Compromise and Defensive Guidance
The US CISA has published STIX packages with known Gunra indicators, including IPs, domains and file hashes, for import into organisational detection systems. Notably, specific IOCs are provided in downloadable formats referenced in the official advisory AA26-222A.
Fortinet’s PSIRT advisories and release notes confirm fixes for the affected versions. Organisations should urgently apply the latest updates for FortiOS and FortiProxy, especially if Security Fabric or remote access features are in use. Additional recommended actions include:
- Patching internet-exposed Fortinet appliances to the latest secure versions
- Restricting and monitoring RDP access, especially to identity and IT administration systems
- Importing CISA-provided indicators into detection tooling
- Segmenting networks to prevent lateral movement from remote access infrastructure
Why This Matters and What Organisations Should Do
Gunra’s use of session theft and RDP lateral movement highlights the risks posed by unpatched perimeter devices and weak remote access controls. The attack chain demonstrates how a single vulnerable VPN or proxy can lead to full compromise of an organisation’s identity infrastructure and IT workstations, with rapid deployment of ransomware and data theft.
Organisations using Fortinet appliances, especially those with virtual desktop or remote access portals, should prioritise patching, restrict RDP to only essential users and systems, and monitor for signs of session theft and unusual lateral movement. Importing official indicators and reviewing authentication and account activity on Fortinet devices is critical to detect and prevent further compromise.
Originally reported by cybersecuritynews.com.






