An unauthenticated threat actor, armed with nothing more than two device serial numbers, can bypass Fortinet authentication, hijack your SSL-VPN sessions, exfiltrate terabytes of sensitive data, and encrypt your entire environment — all before your on-call engineer finishes reading the first alert. That is not a hypothetical. It is the documented playbook of Gunra ransomware, a fast-growing Ransomware-as-a-Service (RaaS) operation now the subject of a rare, six-agency joint advisory issued on August 10, 2026, by the FBI, CISA, NSA, U.S. Department of Defense Cyber Crime Center (DC3), U.S. Secret Service, and the Republic of Korea’s National Police Agency (advisory number AA26-222A). When six agencies on two continents jointly issue a red-alert, IT leaders should not be reading the summary — they should already be patching.

Key Takeaways

  • CVE-2025-24472 (CVSS 8.1) — a Fortinet FortiOS/FortiProxy authentication bypass — is Gunra’s primary network entry point.
  • Once inside, operators leverage built-in FortiOS tools and Impacket SMB utilities to move laterally at speed, compromising domain controllers and backup infrastructure.
  • Data is siphoned to Microsoft OneDrive, SharePoint, and MEGA before encryption; victims who do not pay within 5–7 days face public leak.
  • Gunra operators have compromised 51 confirmed victims across healthcare, financial services, government facilities, and professional services since April 2025.
  • Patch FortiOS to 7.0.17+ and FortiProxy to 7.2.13+ immediately; rotate SSL-VPN credentials; segment OT networks.
  • India’s government and critical infrastructure operators are at elevated risk given overlapping sector targeting and recent state-linked activity in the Asia-Pacific region.

What Is Gunra Ransomware — and Why Does It Move So Fast?

Gunra first appeared in April 2025 and spent its first year building quietly. By early 2026, the group shifted to a formal Ransomware-as-a-Service affiliate model, advertising on dark web forums and recruiting financially motivated operators willing to share a cut of ransom proceeds. The result is a decentralised threat: the core Gunra developers supply the tooling and leak infrastructure; affiliates supply the access and operational tradecraft. This RaaS dynamic makes attribution harder and attack volume higher.

With 51 confirmed victims logged on Ransomware.Live — concentrated in South Korea, Brazil, Spain, Thailand, Hong Kong, and Australia — the group has a demonstrably Asia-Pacific focus. The joint advisory notes only three North American victims to date, suggesting that organisations in Asia, Europe, and the Middle East (including India) may have a false sense of safety. Gunra’s use of commercially available tunnelling tools (Cloudflare Workers, MEGA) and VPN exit nodes (Mullvad, NordVPN) to blend into legitimate traffic makes detection with signature-based tools alone unreliable.

The Six-Stage Attack Chain — From FortiOS Login to Encrypted Backups

The joint advisory (AA26-222A) maps a remarkably consistent intrusion sequence across observed incidents:

  1. Initial Access: Gunra operators exploit CVE-2025-24472 against internet-facing FortiOS and FortiProxy appliances, or deliver phishing payloads to obtain credentials. In parallel, Schneider Electric PowerLogic P5 protection relays on converged IT/OT networks are also targeted via CVE-2024-5559, providing a foothold into operational technology environments.
  2. Credential Harvesting: Operators manipulate the SSL-VPN portal to intercept session credentials and steal cookies. They target Hiware system access control servers, running Impacket’s secretsdump.py to dump hashed passwords and brute-force or relay them. Default credentials on SSL-VPN appliances are also tested.
  3. Lateral Movement: Using Impacket’s psexec.py and smbclient.py, operators traverse the network via SMB. VDI environments are compromised by targeting IT personnel sessions. Account enumeration (secretsdump.py, T1087) enables privilege escalation to domain administrator.
  4. Persistence: OpenSSH is installed on compromised hosts. MFA is bypassed by manipulating OTP mechanisms on VDI portals. The group uses the “MSP Support” default account name in some environments as a cover for Take Control sessions.
  5. Exfiltration: A custom executable named main.exe automates theft of data from Microsoft OneDrive and SharePoint. Compressed archives are uploaded directly to MEGA. The advisory notes terabyte-scale collection capability — operators have been observed staging data for days before triggering encryption.
  6. Encryption and Extortion: Gunra deploys Salsa20 or ChaCha20 stream cipher encryption, capable of encrypting up to 9 TB within a compressed timeframe. Backup systems — including disaster recovery centres — are targeted and deleted first. Victims receive a ransom note with a 5–7 day countdown; non-payment results in data publication on Gunra’s dark-web leak portal.

Technical Breakdown: CVE-2025-24472 — The FortiOS Authentication Bypass

The centrepiece of Gunra’s initial access is CVE-2025-24472, a CWE-288 Authentication Bypass Using an Alternate Path or Channel flaw in Fortinet FortiOS and FortiProxy. With a CVSS v3.1 score of 8.1 and attack complexity rated High, the flaw requires no prior authentication and no user interaction.

Detail Value
CVE ID CVE-2025-24472
CVSS v3.1 Score 8.1 (High)
Attack Vector Network, High Complexity, No Authentication Required
Affected Products FortiOS 7.0.0–7.0.16 & FortiProxy 7.0.0–7.0.19, 7.2.0–7.2.12
Fixed Versions FortiOS 7.0.17+ / FortiProxy 7.2.13+
Technical Root Cause Crafted Cluster Synchronisation Framework (CSF) proxy requests bypass auth and grant super-admin privileges on downstream devices
CISA KEV Status Added to CISA KEV Catalog — active exploitation confirmed

The exploit works because FortiGate units participating in a Security Fabric cluster expose a CSF synchronisation endpoint that is meant to be accessible only between trusted peer appliances. An attacker who can craft a valid-looking CSF proxy request — and who knows or can enumerate the serial numbers of upstream and downstream devices — can submit requests that the target appliance processes with super-administrator privileges. Once the attacker has that session token, the entire FortiGate management plane is open: firewall rules, routing, VPN configuration, user accounts.

This is not a theoretical risk. CISA confirms active, in-the-wild exploitation of CVE-2025-24472 as part of Gunra’s campaign. If you have Security Fabric enabled and your FortiOS version falls within the vulnerable range, treat it as compromised until patched and verified.

Related reading: Earlier this month we documented how a separate FortiOS symlink technique (CVE-2025-68686) can revive backdoors on already-patched devices — a reminder that Fortinet’s SSL-VPN stack continues to be one of the most actively targeted attack surfaces globally.

OT/ICS in the Crosshairs: Why Schneider Electric Matters

The advisory’s reference to Schneider Electric PowerLogic P5 protection relays should alarm any organisation running industrial control systems or building management infrastructure. The inclusion of an OT device in a ransomware attack chain signals a deliberate effort to bridge the IT/OT boundary — a tactic increasingly favoured by financially motivated groups who understand that encrypting an operational technology environment raises the pressure to pay dramatically. Power distribution, manufacturing, water treatment, and data-centre cooling systems that depend on protection relays cannot be offline for weeks while an organisation recovers. Gunra is banking on that urgency. Operators with PowerLogic P5 devices connected to networks that also reach IT systems should treat this advisory as a mandate to audit and segment those paths immediately.

Why India’s IT Leaders Cannot Afford to Wait

India’s BFSI sector, central and state government agencies, healthcare networks, and power utilities share a common profile with Gunra’s confirmed victims. The advisory specifically names healthcare, financial services, and government facilities as priority target sectors — sectors that India has been rapidly digitising under programmes like DIGI-YATRA, Ayushman Bharat Digital Mission, and the National Cybersecurity Policy 2023 framework. A large number of Indian enterprises continue to run Fortinet perimeter appliances — many of them without a rigorous quarterly patch cycle. The combination of internet-facing FortiOS, enabled Security Fabric, and infrequent patching is precisely the configuration Gunra operators are hunting for. The good news is this: the defensive fix is known, free, and available right now.

For comparison: When INC Ransomware weaponised SonicWall zero-days earlier this month, organisations with robust network segmentation and immutable backup policies recovered significantly faster. The playbook holds for Gunra.

What You Should Do Right Now — Sanjay’s Expert Angle

As a zero-trust architect and Fortinet specialist, I regularly see the same gap: organisations know patching matters, but version-sprawl across hundreds of FortiGate units means the vulnerable appliance almost always exists somewhere. Here is a prioritised action list based on the AA26-222A advisory and real-world incident response patterns:

  • Emergency patch — today: Upgrade all FortiOS instances to 7.0.17 or later and FortiProxy to 7.2.13 or later. Verify the version via CLI (get system status) and do not rely solely on the management dashboard.
  • Audit Security Fabric exposure: If you have Security Fabric clustering enabled, confirm that the CSF synchronisation port (TCP 8013) is firewalled from untrusted networks. Disable Security Fabric on perimeter appliances that do not require it.
  • Rotate all FortiOS credentials: Because CVE-2025-24472 can grant super-admin tokens, any session credential on an appliance that was running a vulnerable version should be considered potentially stolen. Reset all admin accounts and revoke active sessions.
  • Audit SSL-VPN for session hijacking indicators: Review authentication logs for anomalous OTP prompts, unexpected session cookies, or MFA bypass events. Correlate with the known Gunra IP indicators: 173.249.252[.]200, 87.249.138[.]34, 37.19.210[.]32, 68.235.46[.]214.
  • Hunt for Impacket and cloudflared: Look for psexec.py, smbclient.py, and secretsdump.py artefacts on domain controllers. Check for the presence of the Cloudflare tunnel binary (cloudflared) under user profile directories.
  • Validate backup isolation: Gunra targets both primary and disaster-recovery backup systems before encrypting. Ensure at least one backup copy is physically or logically air-gapped and cannot be reached from a compromised domain administrator account.
  • Segment OT networks: If PowerLogic or other ICS/SCADA devices share network adjacency with IT systems, place them behind a unidirectional data diode or at minimum a dedicated firewall zone with allow-list-only rules.

Frequently Asked Questions

Is CVE-2025-24472 only exploitable if Security Fabric is enabled?

Yes — the authentication bypass targets the Cluster Synchronisation Framework (CSF) endpoint, which is only active when Security Fabric clustering is configured. However, many enterprise FortiGate deployments enable Security Fabric for telemetry and centralised management without realising it exposes this attack surface. Assume it is enabled unless you have explicitly audited and disabled it.

My FortiGate is behind a NAT firewall — am I still at risk?

If the CSF port (TCP 8013) or the management interface is reachable from untrusted networks — even indirectly through a VPN or jump server — you remain at risk. Patch first; restrict access second. Defence-in-depth is not a substitute for patching a CVSS 8.1 actively exploited vulnerability.

Gunra’s victim list is mostly South Korean organisations. Does that mean Indian companies are lower priority?

No. RaaS affiliates pursue targets of opportunity, and the joint advisory explicitly warns organisations globally. The South Korean concentration reflects either affiliate targeting choices to date or higher detection rates in South Korea — not a geographic safe harbour for Indian organisations. CERT-In and India’s national cybersecurity agencies have not yet issued a parallel advisory, but the CISA advisory is binding guidance for any organisation aligned to global security frameworks.

What is the typical Gunra ransom demand?

The joint advisory and public reporting do not disclose specific ransom figures, which varies by victim size and data sensitivity. However, Gunra operates a double-extortion model: even if you restore from backups, the threat of publishing your exfiltrated data remains. This underscores the need for preventive controls — specifically, stopping the exfiltration phase before it completes.


Is Your Fortinet Environment Gunra-Ready?

A misconfigured FortiOS cluster or an unpatched SSL-VPN appliance is all Gunra needs. At Sanjay Seth Consulting, we perform targeted Fortinet security assessments that cover Security Fabric exposure, SSL-VPN hardening, credential hygiene, and zero-trust segmentation — precisely the controls that stop attacks like this one before data ever leaves your network.

Request a Free Security Assessment →