On August 10, 2026, cybersecurity agencies from five countries published joint advisory AA26-222A on Gunra, a ransomware-as-a-service operation that has listed 51 confirmed victims since its debut in April 2025. The government dossier — signed by CISA, FBI, NSA, USSS, DC3, and South Korea's National Police Agency (KNPA) — documents an attack chain unprecedented in sophistication: two Fortinet vulnerabilities with public exploits serve merely as the entry point, while the structural damage occurs through persistent compromise of the authentication infrastructure, including systematic MFA bypass. The most disturbing operational finding, emerging from field investigations, is that organizations that correctly patched their Fortinet devices remain exposed if they have not verified the presence of persistence mechanisms installed before the update.
- Gunra has operated as RaaS since January 2026 with a structured affiliate program; 51 confirmed victims on data leak site, concentrated in Asia-Pacific and Europe
- Initial access exploits CVE-2024-55591 (CVSS 9.6, super-admin authentication bypass via Node.js websocket) and CVE-2025-24472 (bypass via CSF proxy requests with knowledge of device serial number)
- The group bypasses MFA by altering VDI authentication processing files to accept a Gunra-designated OTP value, not the user's legitimate token
- Persistence includes SSH tunnels, credential harvesting from Hiware access control servers, and scheduled nocturnal activity between 22:00 and 06:00 victim local time
- The double-extortion model combines ChaCha20/Salsa20 encryption with exfiltration of tens of terabytes via OneDrive, SharePoint, and MEGA
The Dual Fortinet Flaw as Master Key
CVE-2024-55591 is classified as CWE-288 (authentication bypass by alternate path) with a CVSS 3.1 score of 9.6 per the official CVE.org record: remote unauthenticated attack, low complexity, total impact on confidentiality, integrity, and availability. The vulnerability resides in the handling of Node.js websocket requests which, when crafted, grant super-admin privileges on FortiOS 7.0.0-7.0.16 and FortiProxy 7.0.0-7.0.19, 7.2.0-7.2.12. CVE-2025-24472, the second flaw in Gunra's arsenal, enables super-admin elevation through CSF (Central Management) proxy requests when the attacker knows the target device's serial number.
Both vulnerabilities have public exploits. According to advisory AA26-222A, Gunra uses them sequentially or alternatively to gain the initial foothold on target networks. The unsettling finding is not the severity of the flaws — both known for months — but the observation that their remediation does not automatically invalidate an access already achieved.
The MFA Bypass That Makes Patching Insufficient
The most sophisticated element of the Gunra chain emerges in the lateral movement and consolidation phase. The group does not merely exploit stolen credentials: it directly modifies VDI (Virtual Desktop Infrastructure) authentication processing files to force acceptance of an OTP value designated by Gunra, independent of the token generated by the legitimate MFA apparatus. This mechanism, documented in the joint advisory with MITRE ATT&CK mapping, turns the authentication infrastructure itself into an open portal for the operators.
Jacob Krell of Suzu Labs, quoted by Infosecurity Magazine, summarized the problem: "Patching fixes the entry point. It does nothing about an authentication backdoor already embedded in the MFA flow. I've seen organizations close the vulnerability and declare themselves clean while the attacker's persistence mechanism sat untouched in the auth stack." The source does not specify the frequency of this scenario in the Gunra cases analyzed, but the mechanism's presence in a government advisory confirms that post-patch persistence is an observed pattern, not theoretical.
The group reinforces control by installing SSH tunnels, extracting enterprise credentials from Hiware access control servers (an identity management system prevalent in Asian industrial environments), and deploying ransomware variants on database servers and NAS. The CISA advisory explicitly describes: "The Gunra actors then leveraged enterprise server credentials stolen from a system access control server to deploy ransomware to encrypt key assets, including database servers and network-attached storage (NAS) systems."
The Operational Machine: Chronotypes, Exfiltration, and Backup Destruction
Gunra operates under the alias "Golden Community" and launched its RaaS affiliate program in January 2026, recruiting penetration testers as initial access brokers. The organizational structure includes full technical support for affiliates, lowering the skill threshold for participation — as reported by CloudSEK researchers cited by Dark Reading.
The temporal behavior is rigid and calculated: the advisory confirms the group conducts malicious activity "primarily between the hours of 10:00 PM and 6:00 AM" victim local time. Roman Sannikov of iCOUNTER commented: "If your detection coverage drops off overnight, that's exactly the gap this group, now also operating under the alias Golden Community, is built to exploit." The source does not quantify the success rate of this strategy.
Exfiltration leverages legitimate cloud infrastructure: Microsoft OneDrive and SharePoint via an executable named 'main.exe', and MEGA for compressed archives on the scale of tens of terabytes — with at least one documented case of exfiltration of approximately tens of terabytes per Infosecurity Magazine. Before and after cryptographic payload deployment, Gunra deletes backups at both primary sites and disaster recovery centers. The Linux variant employs 100 encryption threads with a partial scheme (Salsa20/ChaCha20 with RSA keystore), per Trend Micro analysis cited by The Register. A March 2026 investigation by Breakglass Intelligence identified a "catastrophic cryptographic weakness" in the Linux variant that enables key recovery — the dossier does not specify whether this weakness has been fixed in current builds.
"Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations" — Chris Butera, CISA Acting Executive Assistant Director for Cybersecurity
Victim Geography and Extortion Pressure
The 51 confirmed victims on the data leak site — per Ransomware.Li data cited by The Hacker News — show a skewed geographic distribution: absolute majority in Australia, East Asia, and Europe; Brazil, Spain, Thailand, and Hong Kong as significant presences; only 3 total victims across Canada and the United States. This profile suggests that Gunra, while monitored at the U.S. government level, has concentrated operational activity in regions with massive Fortinet infrastructure presence and, possibly, less structured nocturnal detection posture.
Ransom demands start at arbitrarily high figures, described as "tens of millions of dollars" by Infosecurity Magazine, with a 5-7 day negotiation window before leak site publication. The negotiation portal is hosted on Tor. The dossier provides no data on payment rates or total revenue generated.
Immediate Actions
Advisory AA26-222A provides specific operational guidance for organizations with Fortinet appliances in their perimeter. The actions documented by the primary source are:
- Review the entire VDI and Hiware authentication chain to identify unauthorized modifications to OTP processing files, regardless of the Fortinet vulnerability patching date
- Inspect for active SSH tunnels or residual configurations, verifying suspicious connections in the 22:00-06:00 time windows
- Validate integrity of primary and disaster recovery backups, checking that restore procedures have not been altered or invalidated
- Consult the IOCs (Indicators of Compromise) and STIX artifacts published in CISA advisory AA26-222A for verification on detection systems
The Patch Gap Problem as New Standard
Gunra's emergence redefines the very concept of a "patched system." If compromise of the authentication infrastructure survives the perimeter firmware update, patching becomes a necessary but insufficient condition. The coldest reading is that organizations have invested in vulnerability-centric remediation cycles without parallel verification of the entire authentication stack's integrity. Gunra exploits exactly this asymmetry: the first Fortinet flaw costs little effort, but the real investment lies in the silent persistence that follows.
The participation of South Korea's KNPA in the joint advisory — alongside U.S. agencies — underscores that the phenomenon has transnational dimension and measurable industrial impact. The RaaS model, with its formalized affiliate program, exposes a homologous population of operators wider and less predictable than traditional ransomware groups. The dossier does not clarify any links, if they exist, with North Korean state actors: some instrumental overlaps with Lazarus Group are reported as rumor, but no documented infrastructure overlaps connect Gunra to Pyongyang in the current state of investigations.
Information verified against cited sources and current as of publication.
Sources
- https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html
- https://www.infosecurity-magazine.com/news/gunra-ransomware-fortinet-flaws/
- https://www.bankinfosecurity.com/alert-unpatched-fortinet-devices-fall-to-gunra-ransomware-a-32518
- https://www.darkreading.com/cyberattacks-data-breaches/gunra-ransomware-gang-fortinet-flaws-bypasses-mfa
- https://www.theregister.com/cyber-crime/2026/08/11/feds-warn-gunra-ransomware-is-exploiting-known-bugs-to-hit-critical-infrastructure/5286263
- https://www.cve.org/CVERecord?id=CVE-2024-55591
- https://www.cisa.gov/news-events/news/cisa-fbi-and-partners-warn-organizations-gunra-ransomware-actors-targeting-multiple-critical
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
- https://www.bankinfosecurity.com/
- https://www.bankinfosecurity.co.uk/