Gunra Ransomware Exploits Fortinet Flaws for RDP Attacks

Gunra ransomware uses stolen sessions and RDP to pivot into AD via Fortinet edge

Gunra ransomware is rapidly becoming a significant enterprise threat, exploiting Fortinet vulnerabilities to steal remote sessions and pivot via RDP into Active Directory and IT workstations. The operation’s technical sophistication and double extortion tactics pose acute risks to organisations using FortiOS and FortiProxy devices.

Gunra Ransomware: Exploiting Fortinet Devices for Initial Access

First observed in April 2025, Gunra is a ransomware-as-a-service (RaaS) group derived from leaked Conti source code. It targets both Windows and Linux environments and has been linked to attacks on government, critical infrastructure, healthcare and private sectors globally. Gunra’s affiliates are known for breaching organisations by exploiting authentication bypass vulnerabilities in Fortinet FortiOS and FortiProxy devices, specifically CVE-2024-55591 and CVE-2025-24472.

These vulnerabilities allow remote, unauthenticated attackers to gain super admin privileges on affected Fortinet appliances. CVE-2024-55591 enables attackers to use crafted requests targeting the Node.js websocket module. CVE-2025-24472, disclosed in February 2025, impacts deployments with Security Fabric enabled, allowing super admin access with knowledge of specific device serial numbers. Both vulnerabilities have seen active exploitation in the wild, with CVE-2024-55591 observed as a zero day from at least November 2024.

Attack Chain: Session Theft and RDP Lateral Movement

Gunra affiliates’ attacks begin with the compromise of internet-facing Fortinet appliances. Once access is gained, they create persistent superuser accounts and manipulate the device’s remote access features. This enables them to collect credentials and active session data from users authenticating to virtual desktop portals.

Stolen sessions are then reused to enter internal virtual desktop infrastructure (VDI) environments. From there, attackers pivot laterally using Remote Desktop Protocol (RDP), targeting:

  • VDI authentication web servers
  • Active Directory domain controllers
  • IT administration workstations

Before detonating ransomware, Gunra operators exfiltrate large volumes of sensitive data, including documents, databases and email. The ransomware payload uses a multithreaded ChaCha20 encryption scheme with RSA-protected keys, appending .ENCRT to affected files. Victims face double extortion: not only are files encrypted, but there is also the threat that stolen data will be published or sold if the ransom is not paid.

Technical Details of Fortinet Vulnerabilities

  • CVE-2024-55591: Impacts FortiOS 7.0.0–7.0.16 (fixed in 7.0.17) and FortiProxy 7.0.0–7.0.19, 7.2.0–7.2.12. Enables authentication bypass via crafted websocket requests.
  • CVE-2025-24472: Impacts FortiOS and FortiProxy in the same version ranges when Security Fabric is enabled. Attackers can use knowledge of device serials to send CSF proxy requests and gain admin access.

Fortinet released patches for CVE-2024-55591 in January 2025 and for CVE-2025-24472 in February 2025. Despite this, active exploitation has continued, particularly targeting organisations slow to upgrade or with exposed edge devices.

Event Timeline and Exploitation Status

  • 14 January 2025: Fortinet discloses and patches CVE-2024-55591 after observing in-the-wild attacks.
  • February 2025: CVE-2025-24472 disclosed and patched.
  • April 2025: Gunra activity detected in Windows environments.
  • Mid 2025: Linux variant emerges.
  • January 2026: Gunra RaaS affiliate programme launched.
  • 10 August 2026: US and South Korea issue a joint advisory detailing Gunra’s exploitation of Fortinet flaws and RDP pivoting.

Government and industry reporting confirms that both vulnerabilities have been, and continue to be, actively exploited. Gunra affiliates have targeted a wide range of sectors worldwide, with the NHS National CSOC warning of ongoing exploitation and high risk to UK organisations.

Indicators of Compromise and Defensive Guidance

The US CISA has published STIX packages with known Gunra indicators, including IPs, domains and file hashes, for import into organisational detection systems. Notably, specific IOCs are provided in downloadable formats referenced in the official advisory AA26-222A.

Fortinet’s PSIRT advisories and release notes confirm fixes for the affected versions. Organisations should urgently apply the latest updates for FortiOS and FortiProxy, especially if Security Fabric or remote access features are in use. Additional recommended actions include:

  • Patching internet-exposed Fortinet appliances to the latest secure versions
  • Restricting and monitoring RDP access, especially to identity and IT administration systems
  • Importing CISA-provided indicators into detection tooling
  • Segmenting networks to prevent lateral movement from remote access infrastructure

Why This Matters and What Organisations Should Do

Gunra’s use of session theft and RDP lateral movement highlights the risks posed by unpatched perimeter devices and weak remote access controls. The attack chain demonstrates how a single vulnerable VPN or proxy can lead to full compromise of an organisation’s identity infrastructure and IT workstations, with rapid deployment of ransomware and data theft.

Organisations using Fortinet appliances, especially those with virtual desktop or remote access portals, should prioritise patching, restrict RDP to only essential users and systems, and monitor for signs of session theft and unusual lateral movement. Importing official indicators and reviewing authentication and account activity on Fortinet devices is critical to detect and prevent further compromise.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call