Skip to content
Beveiligingsnieuws

Gunra ransomware: Fortinet & Schneider exploits

Gunra ransomware

Security and intelligence agencies from South Korea and the U.S. have issued warnings about Gunra ransomware campaigns aimed at critical organizations worldwide. The activity is not limited to one region or industry; instead, it spans sectors such as healthcare and public health, financial services, government services, and professional and nonprofit organizations.

Reports also highlight a disruption-focused pattern that follows initial access with data theft and encryption. If victims do not pay within a short window, attackers publish stolen data on leak sites, increasing both operational and reputational damage.

Who is being targeted by Gunra ransomware?

The agencies describe targets across many categories, including organizations that manage sensitive operational and public services. Healthcare providers, government facilities, and financial institutions are among the named sectors, along with professional and nonprofit organizations.

When looking at reported victims, the pattern is heavily concentrated in parts of Asia as well as other international regions. According to data cited from Ransomware.Live, Gunra had listed 51 victims since appearing in April 2025, with most victims attributed to South Korea, Brazil, Spain, Thailand, and Hong Kong.

Investigators note that Australia, East Asia, and Europe account for the majority of victims, while only a small number of cases were reported from Canada and the U.S. at the time of publication.

How Gunra ransomware gets in: appliance vulnerabilities

A core element of the campaign is how attackers obtain initial access. In these incidents, attackers leveraged security issues in internet-facing infrastructure, including devices from both Fortinet and Schneider Electric.

Specifically, the activity references:

  • Schneider Electric PowerLogic P5 vulnerability: CVE-2024-5559
  • Fortinet FortiOS and FortiProxy vulnerabilities: CVE-2025-24472

Once attackers gain a foothold, they proceed to deepen access and prepare for the ransomware phase. This approach fits a broader double extortion model where stolen information becomes an additional weapon alongside file encryption.

Double extortion: encryption plus data leaks

Unlike ransomware campaigns that focus on encryption alone, Gunra ransomware is described as using data exfiltration and encryption together to maximize impact. Attackers steal information, then encrypt key assets to halt operations.

Victims who do not respond within roughly five to seven days are reported to have their data published on a dedicated leak site. This timeline adds pressure not only on IT teams but also on leadership and communications departments.

Attackers use phishing and negotiation routines

Initial access is not only tied to exposed systems. One analysis referenced in the report points to phishing as a main delivery method for malicious components sent to targets.

After compromise, the group is also described as conducting negotiation through a chat experience themed around WhatsApp. This aligns with how modern ransomware operators manage pressure and payment discussions with victims.

Encryption at scale and cryptographic details

The technical description includes how encryption can be carried out quickly, including the ability to process very large files. The report mentions stream cipher approaches such as Salsa20 or ChaCha20 for encryption activities within constrained time windows.

Additionally, the ransomware operation is linked to a RaaS-style affiliate model. It is described as operating an affiliate program that provides partners with tooling and documentation, including a management panel and a configurable ransomware builder.

Affiliate model and platform variations

The referenced activity describes a formal affiliate program launched in January 2026 on dark web forums. Affiliates reportedly receive access to components used to distribute the ransomware, including cross-platform locker payloads and structured instructions.

The report also mentions that Windows and Linux variants exist. In at least one separate analysis, a severe cryptographic weakness was discussed for Linux builds, including a claim that it was possible to recover an encryption key and regain access to encrypted files.

Credential theft and lateral movement tactics

Once inside a network, Gunra ransomware campaigns are described as relying on common post-exploitation behaviors to expand access and escalate privileges.

For lateral movement, the activity references the use of Impacket tools such as psexec.py and smbclient.py via the SMB protocol. For credential access, it cites secretsdump.py to extract password hashes from domain controllers by pulling information from the NTDS file.

In parallel, operational security behaviors appear designed to reduce visibility. The group is reported to delete system and network access logs and clear command history, making incident response harder.

Covering tracks and timing patterns

The report notes that malicious activity is primarily conducted during overnight hours, specifically between 10 p.m. and 6 a.m. This kind of scheduling can help attackers blend into normal low-usage periods and potentially delay detection.

Exfiltration is described as being carried out through an executable named main.exe, with references to theft from Microsoft OneDrive and SharePoint.

Data exfiltration methods: MEGA and large archives

Attackers are described as collecting business-critical documents and, in some cases, creating compressed archives that can reach terabyte-scale. Those archives may be exfiltrated to consumer file-sharing services, including MEGA as cited.

The report also highlights targeting of virtual desktop infrastructure environments used by IT personnel. From those environments, attackers reportedly harvest sensitive configuration-related documents.

Targeting enterprise servers and storage systems

After stealing enterprise credentials, the attackers reportedly deploy ransomware that encrypts key assets. The report specifically mentions database servers and network-attached storage (NAS) systems as high-value targets.

This is consistent with how organizations can lose both application availability and supporting data access in a single incident.

Abusing VPN and VDI authentication weaknesses

In at least one observed case involving South Korea’s National Police Agency, attackers manipulated network traffic control features of an SSL-VPN appliance. The goal was to intercept credentials and session information used when users authenticate to a corporate VDI portal.

With stolen session cookies, attackers could perform session hijacking and impersonate legitimate users to reach internal systems.

The report also describes attempts to bypass multi-factor authentication by tampering with authentication processing files on the VDI portal server. In the described scenario, the authentication succeeded when a specific Gunra-designated OTP value was used.

Additional behaviors seen during intrusions

Beyond the vulnerability and authentication abuse, the report lists other detected actions. Examples include:

  • Gaining admin access to an SSL-VPN appliance using default credentials, then pulling OpenSSH from an attacker-controlled server to maintain persistence.
  • Leveraging an unused account in an SSL-VPN administrative interface and modifying configuration to bypass mandatory password change requirements.
  • Accessing an enterprise access control server via SSH from a compromised virtual desktop and stealing an encryption key used to decrypt passwords stored in a database.
  • Deleting backup and archived data at both the primary data center and disaster recovery sites before and after ransomware deployment.

Possible links to wider campaigns

The report points out a broader context involving campaigns described by South Korea as state-sponsored. Those campaigns allegedly used spear-phishing and watering hole techniques, along with vulnerabilities in financial security software, to deliver malware across a multi-year window.

It is also stated that some incidents shared overlaps with the same financial security software vulnerabilities used to deliver Gunra ransomware and exfiltrate organizational information. AhnLab is also quoted as suggesting shared techniques, tools, infrastructure, or limited collaboration, even if the apparent end goals differ.

Separately, some watering hole behavior reportedly exploited a zero-day vulnerability in AnySign4PC, installing payloads when certificate signing software was present. The report names malware families including Struggle (SIGNBT 3.0) and Brandoor (COPPERHEDGE), which have been associated with the Lazarus Group.

How to reduce risk from Gunra ransomware

While the details vary by victim environment, the recommended defenses focus on reducing exposure to known exploited weaknesses and limiting the blast radius of a breach.

Organizations are advised to:

  • Keep operating systems, software, and firmware fully up to date.
  • Prioritize patching for known vulnerabilities affecting internet-facing systems, including the referenced Fortinet and Schneider Electric issues.
  • Enforce network segmentation to limit lateral movement after an intrusion.
  • Ensure backups are immutable and stored in a physically separate location.

In practice, these measures help stop initial compromise paths, reduce credential and server reach, and improve recovery outcomes if encryption occurs.

Conclusion

The warnings emphasize that Gunra ransomware is more than a file-encryption event. With exploitation of public-facing appliance vulnerabilities, phishing-driven initial access, double extortion pressure, and credential-driven lateral movement, the campaign targets both availability and confidentiality.

By focusing on rapid patching, hardening internet-facing systems, segmenting networks, and protecting backups with immutability and separation, organizations can significantly reduce the likelihood that an attacker reaches the stage where encryption and leak-site publication become inevitable.

Source: https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html