News Room
16
Share
Global Security Alert: Gunra Ransomware Exploits Critical Fortinet Vulnerabilities
criticalThreat Intelligence

Global Security Alert: Gunra Ransomware Exploits Critical Fortinet Vulnerabilities

U.S. and South Korean authorities have issued a joint advisory regarding the Gunra ransomware, which is actively exploiting Fortinet vulnerabilities to breach government and critical infrastructure networks.

17 August 2026Last updated 18 August 20264 min readCISA
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
Confirmed
Source:
CISA
Read Time:
4 min

Executive Summary

In a coordinated effort, U.S. federal agencies and the Republic of Korea’s National Police Agency have issued a high-priority security advisory regarding the Gunra ransomware. This threat actor is currently leveraging critical vulnerabilities in Fortinet FortiOS and FortiProxy to gain unauthorized access to government and critical infrastructure organizations globally. The campaign, which has intensified throughout August 2026, highlights a shift toward exploiting edge-network appliances to facilitate large-scale, double-extortion attacks.

Threat Analysis

Gunra, which first emerged in April 2025, has evolved into a sophisticated Ransomware-as-a-Service (RaaS) operation. By utilizing source code derived from the legacy Conti ransomware, the group has successfully scaled its operations. The current campaign focuses on the exploitation of unpatched Fortinet devices, allowing attackers to bypass perimeter defenses. Once inside, the group employs double-extortion tactics, exfiltrating sensitive data before deploying encryption payloads to maximize leverage during ransom negotiations.

Technical Details

The primary attack vector involves the exploitation of known vulnerabilities in Fortinet’s operating systems. Upon successful exploitation, the attackers establish persistence within the network, often moving laterally to identify high-value assets. The ransomware payload is typically deployed via automated scripts that disable security software and shadow copies. The group has been observed using custom exfiltration tools to move data to remote servers before the final encryption phase, ensuring they have sufficient leverage even if the victim restores from backups.

Attribution Assessment

Intelligence indicates that Gunra operates as a structured RaaS model, recruiting affiliates through dark web forums. While the group’s origins are linked to the leaked Conti source code, its current operational tempo suggests a highly organized, financially motivated cybercriminal enterprise. The group’s victimology spans the Americas, Europe, the Middle East, Africa, and the Asia-Pacific, indicating a global reach and a high level of operational maturity.

Implications

The exploitation of edge-network devices like Fortinet appliances poses a significant risk to organizations that rely on these systems for secure remote access. The ability of Gunra to rapidly pivot from initial access to full-scale encryption threatens the operational continuity of critical infrastructure. Furthermore, the group’s commitment to double-extortion means that even organizations with robust backup strategies remain vulnerable to data leaks.

Recommendations

Organizations are urged to immediately audit their network infrastructure for unpatched Fortinet devices and apply the latest security updates provided by the vendor. Security teams should implement strict access controls, enforce multi-factor authentication (MFA) for all remote access, and monitor for anomalous outbound traffic that may indicate data exfiltration. Additionally, organizations should conduct regular threat hunting exercises to identify potential indicators of compromise (IOCs) associated with Gunra activity.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo