Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure
Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data
The US government is cautioning operators of critical infrastructure to apply patches to their internet-accessible systems following the discovery that Gunra ransomware is taking advantage of known software flaws to infiltrate networks. First detected in 2025, Gunra has quickly grown in scope, now functioning as ransomware-as-a-service with affiliates targeting organizations around the world.
These groups have exploited two specific vulnerabilities, CVE-2024-55591 and CVE-2025-24472, which are authentication bypass flaws in Fortinet's FortiOS and FortiProxy devices. Once inside a network, Gunra affiliates follow a standard ransomware tactic, stealing data, encrypting affected systems, and demanding a decryption tool and assurance they will not publish the stolen information.
Negotiations occur through a Tor-based portal, with victims generally given five to seven days before their data is released. Chris Butera, CISA's acting executive assistant director for cybersecurity, noted that Gunra represents the ongoing problem of ransomware attacks causing disruption to both US and international organizations.
Trend Micro first observed Gunra in April 2025, initially targeting Windows systems, but later discovered a Linux variant that can run up to 100 encryption threads at once and supports partial file encryption. This new version also stores RSA-encrypted keys in separate keystore files. Gunra has been active in Turkey, Taiwan, the US, and South Korea, and the attackers have claimed victims in Brazil, Japan, Canada, as well as in manufacturers, healthcare providers, IT companies, and law firms.
To combat these threats, agencies are advising potential targets to patch known exploited vulnerabilities in internet-facing systems, secure VPN gateways and RDP access with multifactor authentication, segment their networks, and maintain offline, immutable backups to make it more difficult for attackers to gain access.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.