
Gunra RaaS Exploits Fortinet Flaws as Qilin and Storm Groups Claim New Global Victims
Intelligence reports confirm Gunra ransomware is actively exploiting Fortinet vulnerabilities to target critical infrastructure, while Qilin and Storm groups have listed new victims in Japan and the US.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- CISA and Unit 42
- Read Time:
- 5 min
Executive Summary
The cybersecurity landscape has witnessed a significant escalation in ransomware activity between August 14 and August 16, 2026. A joint advisory from CISA and South Korean intelligence agencies has highlighted the emergence of Gunra ransomware, a Ransomware-as-a-Service (RaaS) operation exploiting critical vulnerabilities in Fortinet networking equipment. Concurrently, established groups like Qilin and Storm have claimed new victims in Japan and the United States, respectively. These developments underscore a persistent trend of double extortion and the targeting of critical infrastructure sectors, including healthcare and manufacturing.
Threat Analysis
Gunra ransomware, which first appeared in 2025, has rapidly evolved into a sophisticated RaaS model. According to Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks, the group utilizes a double-extortion strategy, where data is both encrypted and exfiltrated to a dedicated leak site (DLS). This pressure tactic is designed to compel payment even if the victim has viable backups. The group's expansion into a structured affiliate program has increased its operational tempo, targeting diverse sectors such as financial services and government facilities across South Korea, Brazil, and the United States.
Technical Details
The primary infection vector for recent Gunra campaigns involves the exploitation of known vulnerabilities in Fortinet FortiOS and FortiProxy. As detailed in the #StopRansomware: Gunra Ransomware advisory, attackers leverage these flaws to gain initial access and move laterally within the network. Once inside, the actors deploy EDR-killing techniques to disable security software, a tactic also observed in other prolific groups like The Gentlemen. In the case of the ASCII Group breach reported on August 16, 2026, infostealer activity was identified as a precursor to the Qilin ransomware deployment, as noted by Ransomware.live - Victim: ASCII Group.
Attribution Assessment
Gunra is currently attributed to financially motivated cybercriminals, though its targeting of South Korean and U.S. infrastructure has drawn significant attention from national intelligence agencies. The Qilin group, which claimed the ASCII Group on August 16, remains a top-tier threat actor with suspected links to Russian-speaking cybercrime ecosystems. Meanwhile, the Storm ransomware group, which targeted the Southern Metals Company on August 14, continues to focus on U.S.-based industrial targets, as reported in Ransomware Group Storm Hits: Southern Metals Company.
Implications
The exploitation of edge networking devices like Fortinet firewalls represents a significant risk to supply chain integrity and critical infrastructure. The ability of RaaS affiliates to rapidly weaponize vulnerabilities means that the window for patching is narrower than ever. Furthermore, the rise of AI-driven extortion and EDR evasion techniques suggests that traditional signature-based defenses are increasingly inadequate against modern ransomware strains.
Recommendations
Encrygma analysts recommend that organizations immediately audit all Fortinet FortiOS and FortiProxy assets for unpatched vulnerabilities. Implementing robust multi-factor authentication (MFA) and network segmentation is critical to preventing lateral movement. Additionally, organizations should integrate real-time threat intelligence feeds to monitor for indicators of compromise (IoCs) associated with Gunra and Qilin. Regular testing of incident response plans and offline backup restoration is essential to mitigate the impact of double-extortion attacks.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors

Ransomware Surge: Emperador and SafePay Lead Record-Breaking September 2026 Extortion Wave

