Published Security3 min read
Gunra is still walking in through Fortinet bugs that have had patches for months
A joint FBI, CISA and Korean National Police advisory puts a Conti-derived ransomware crew inside government and critical infrastructure networks via two patched authentication bypasses.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- A joint advisory authored by the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), other US government agencies and the Republic of Korea's National Police Agency (KNPA) was published on August 10.
- The advisory warns that Gunra ransomware actors are exploiting two legacy Fortinet vulnerabilities to target government and critical national infrastructure organisations; the FBI has observed Gunra specifically targeting these two flaws.
- Gunra is a ransomware-as-a-service operation that primarily exploits known vulnerabilities in internet-facing devices, including firewalls and VPN appliances, to gain initial access.
- Gunra ransomware is based on Conti ransomware source code leaked in 2022, and was first observed in April 2025.
- In early 2026 the group developed a structured RaaS affiliate programme advertised on dark web forums, and adopted new branding aliases including operating under the name "Golden Community".
Compiled by The WatchSomething wrong?How this is made
Why it matters
The FBI, CISA, other US agencies and the Republic of Korea's National Police Agency published a joint advisory on August 10 stating that Gunra ransomware actors are exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organisations [1][2]. Patches exist for both [8]. The interesting part of this advisory is not the malware, it is that a ransomware-as-a-service operation with a structured affiliate programme is still funding itself on edge-appliance patch debt.
Both flaws are authentication bypasses in specific FortiOS and FortiProxy versions. CVE-2024-55591 is rated critical and lets a remote attacker reach super-admin privileges through crafted requests to the Node.js websocket module [6]. CVE-2025-24472 is rated high and lets an unauthenticated remote attacker who knows upstream and downstream device serial numbers obtain super-admin on the downstream device via crafted CSF proxy requests, where Security Fabric is enabled [7]. The advisory describes these as legacy vulnerabilities that the FBI has observed Gunra specifically targeting [2]. Their identifiers alone show they were assigned in 2024 and 2025, before the advisory was written [19].
Gunra itself is built on Conti source code leaked in 2022 and was first observed in April 2025 [4]. In early 2026 the group stood up a structured affiliate programme advertised on dark web forums and picked up new branding, including the alias "Golden Community" [5]. Its stated preference for initial access is known vulnerabilities in internet-facing devices, particularly firewalls and VPN appliances [3].
Where Fortinet is not the door, weak administration is. In one case cited by the advisory, Gunra actors took over an SSL-VPN administrator account using default credentials on an appliance with no account lockout controls, then downloaded OpenSSH to tunnel out to an attacker-controlled server [9][10]. In another, they modified authentication processing files on a corporate VDI authentication portal server to bypass MFA continuously [11].
That second case is the reason patching alone will not close this out. Jacob Krell of Suzu Labs, commenting on the advisory, said patching fixes the entry point and does nothing about an authentication backdoor already embedded in the MFA flow, and that he has seen organisations close the vulnerability and declare themselves clean while the persistence mechanism sat untouched in the auth stack [12][13].
The rest of the playbook is designed against thin coverage. Gunra deletes system and network access logs and clears command history [16], and conducts most of its internal reconnaissance and malicious activity between 10pm and 6am in the victim's time zone, while administrators are offline [17]. That is an eight-hour nightly window, a third of every day [20]. Roman Sannikov of iCOUNTER said that if detection coverage drops off overnight, that is exactly the gap the group is built to exploit [18]. Exfiltration is stealthy and large in volume, notably from Microsoft 365 services [14], supporting a double-extortion demand covering both decryption and non-publication [15].
What to watch: whether affected sectors can show that Fortinet fixes for CVE-2024-55591 and CVE-2025-24472 are actually deployed rather than scheduled [6][7][8], whether anyone audits VDI and MFA authentication files for modification after remediation [11], and whether the Golden Community branding starts appearing on victim listings separately from Gunra [5].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A joint advisory authored by the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), other US government agencies and the Republic of Korea's National Police Agency (KNPA) was published on August 10.
- [2]
The advisory warns that Gunra ransomware actors are exploiting two legacy Fortinet vulnerabilities to target government and critical national infrastructure organisations; the FBI has observed Gunra specifically targeting these two flaws.
- [3]
Gunra is a ransomware-as-a-service operation that primarily exploits known vulnerabilities in internet-facing devices, including firewalls and VPN appliances, to gain initial access.
- [4]
Gunra ransomware is based on Conti ransomware source code leaked in 2022, and was first observed in April 2025.
- [5]
In early 2026 the group developed a structured RaaS affiliate programme advertised on dark web forums, and adopted new branding aliases including operating under the name "Golden Community".
- [6]
CVE-2024-55591 is a critical authentication bypass affecting specific FortiOS and FortiProxy versions that allows a remote attacker to gain super-admin privileges via crafted requests to the Node.js websocket module.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- infosecurity-magazine.comAug 12Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure
Additional citations
- Infosecurity Magazine
- Infosecurity Magazine, citing the joint FBI/CISA/KNPA advisory
- Infosecurity Magazine, citing the advisory
- Jacob Krell, Suzu Labs, quoted by Infosecurity Magazine
- Roman Sannikov, iCOUNTER, quoted by Infosecurity Magazine



