Gunra uses a double-extortion approach: affiliates exfiltrate sensitive data before encrypting systems, then threaten to leak the stolen data if the ransom is not paid . Victims are given a strict five- to seven-day deadline to pay the ransom before data is published on the group's data leak site
.
The primary initial-access vectors are two authentication bypass vulnerabilities in Fortinet FortiOS and FortiProxy products:
CVE-2024-55591 — An authentication bypass affecting FortiOS and FortiProxy Node.js websocket modules, exploited as a zero-day since November 2024 . It allows unauthenticated remote attackers to gain super-admin privileges. This vulnerability carries a CVSSv3 score of 9.6
.
CVE-2025-24472 — An authentication bypass vulnerability (CWE-288) affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12 / 7.0.0 through 7.0.19, allowing remote unauthenticated attackers with knowledge of upstream and downstream device serial numbers to gain super-admin access on the downstream device if the Security Fabric is enabled .
Affiliates use these flaws to create persistent super-admin accounts on exposed FortiGate firewalls and SSL-VPN appliances, bypass MFA by altering authentication processing, and move laterally into enterprise networks . Investigators have observed the creation of a malicious persistent account named
forticloud-sync on compromised devices .
Gunra has targeted organizations globally across multiple critical-infrastructure sectors, including:
Once inside a network, Gunra affiliates use common Windows administration tooling to reach Active Directory, VDI infrastructure, database servers, NAS systems, Microsoft OneDrive, and Microsoft SharePoint . The encryptor uses multithreaded ChaCha20 combined with RSA-4096 for key protection, appends the
.ENCRT extension to encrypted files, and drops a ransom note named R3ADM3.txt . A separate Linux variant targets Linux systems and has a reported weakness: its encryption keys derive from a PRNG initialized with
srand(time(NULL)), potentially making key recovery possible .
To avoid detection, Gunra affiliates employ standard operational security measures:
The advisory was jointly issued by the FBI, CISA, NSA, Department of Defense Cyber Crime Center (DC3), U.S. Secret Service, and the Republic of Korea's National Police Agency (KNPA) . Agencies strongly urge organizations to report incidents to CISA or the FBI rather than negotiating ransom demands
.