Ransomware Exploits Fortinet

Overview

Cybersecurity agencies from South Korea and the United States have issued warnings about Gunra ransomware attacks targeting critical infrastructure worldwide. Victims span healthcare, finance, government services, and nonprofit sectors. Gunra represents the latest evolution in double‑extortion ransomware, combining data exfiltration with encryption to maximize impact.

Initial Access Vectors

Gunra operators exploit known vulnerabilities in:

  • Schneider Electric PowerLogic P5 (CVE‑2024‑5559).
  • Fortinet FortiOS and FortiProxy (CVE‑2025‑24472).

These flaws allow attackers to breach internet‑facing appliances and gain footholds in enterprise networks.

Attack Chain and Techniques

  • Phishing campaigns deliver malicious payloads.
  • Impacket tools (psexec.py, smbclient.py, secretsdump.py) enable lateral movement and credential dumping.
  • Data exfiltration:
    • Executable main.exe used for OneDrive and SharePoint theft.
    • Terabytes of compressed archives exfiltrated to MEGA file‑sharing service.
  • Persistence and stealth:
    • Rogue admin accounts created.
    • Logs and command history deleted.
    • Operations conducted between 10 p.m. and 6 a.m. to avoid detection.
  • MFA bypass: Manipulated VDI authentication files to accept attacker‑designated OTP values.

Victimology

  • Global footprint: 51 victims listed since April 2025.
  • Regions most affected: South Korea, Brazil, Spain, Thailand, Hong Kong.
  • Primary focus: Australia, East Asia, and Europe.
  • Limited impact in North America: Only three victims reported in Canada and the U.S.

Ransomware‑as‑a‑Service (RaaS) Model

Gunra, derived from Conti, launched a formal RaaS affiliate program in January 2026:

  • Provides affiliates with a management panel, ransomware builder, and documentation.
  • Offers Windows and Linux variants (though Linux builds suffer from cryptographic weaknesses).
  • Rebrands under aliases like Golden Community to expand operations.
  • Recruits penetration testers and ethical hackers as initial access brokers.

Links to State‑Sponsored Activity

  • South Korean advisories highlight overlaps with Lazarus Group campaigns.
  • Shared techniques include exploitation of AnySign4PC zero‑day and malware strains like Struggle (SIGNBT 3.0) and Brandoor (COPPERHEDGE).
  • Analysts suggest limited collaboration or shared infrastructure between Gunra and North Korean state‑sponsored actors.

Defensive Guidance

Organizations should:

  • Patch exploited vulnerabilities immediately.
  • Segment networks to contain lateral movement.
  • Enforce immutable backups stored offline or in separate physical locations.
  • Monitor for Impacket tool usage and anomalous SMB traffic.
  • Audit VDI authentication portals for tampering with OTP validation files.

Expert in the Cloud Insight

Gunra ransomware demonstrates how supply‑chain vulnerabilities in appliances and sophisticated affiliate programs converge to threaten global infrastructure. Its blend of technical exploitation, stealth operations, and RaaS monetization makes it a formidable adversary. For defenders, the lesson is clear: patch aggressively, monitor relentlessly, and treat backups as sacred assets.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.