News Room
16
Share
Gunra RaaS Exploits Fortinet Flaws as Qilin and Storm Groups Claim New Global Victims
criticalThreat Intelligence

Gunra RaaS Exploits Fortinet Flaws as Qilin and Storm Groups Claim New Global Victims

Intelligence reports confirm Gunra ransomware is actively exploiting Fortinet vulnerabilities to target critical infrastructure, while Qilin and Storm groups have listed new victims in Japan and the US.

16 August 2026Last updated 18 August 20265 min readCISA and Unit 42
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
High Confidence
Source:
CISA and Unit 42
Read Time:
5 min

Executive Summary

The cybersecurity landscape has witnessed a significant escalation in ransomware activity between August 14 and August 16, 2026. A joint advisory from CISA and South Korean intelligence agencies has highlighted the emergence of Gunra ransomware, a Ransomware-as-a-Service (RaaS) operation exploiting critical vulnerabilities in Fortinet networking equipment. Concurrently, established groups like Qilin and Storm have claimed new victims in Japan and the United States, respectively. These developments underscore a persistent trend of double extortion and the targeting of critical infrastructure sectors, including healthcare and manufacturing.

Threat Analysis

Gunra ransomware, which first appeared in 2025, has rapidly evolved into a sophisticated RaaS model. According to Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks, the group utilizes a double-extortion strategy, where data is both encrypted and exfiltrated to a dedicated leak site (DLS). This pressure tactic is designed to compel payment even if the victim has viable backups. The group's expansion into a structured affiliate program has increased its operational tempo, targeting diverse sectors such as financial services and government facilities across South Korea, Brazil, and the United States.

Technical Details

The primary infection vector for recent Gunra campaigns involves the exploitation of known vulnerabilities in Fortinet FortiOS and FortiProxy. As detailed in the #StopRansomware: Gunra Ransomware advisory, attackers leverage these flaws to gain initial access and move laterally within the network. Once inside, the actors deploy EDR-killing techniques to disable security software, a tactic also observed in other prolific groups like The Gentlemen. In the case of the ASCII Group breach reported on August 16, 2026, infostealer activity was identified as a precursor to the Qilin ransomware deployment, as noted by Ransomware.live - Victim: ASCII Group.

Attribution Assessment

Gunra is currently attributed to financially motivated cybercriminals, though its targeting of South Korean and U.S. infrastructure has drawn significant attention from national intelligence agencies. The Qilin group, which claimed the ASCII Group on August 16, remains a top-tier threat actor with suspected links to Russian-speaking cybercrime ecosystems. Meanwhile, the Storm ransomware group, which targeted the Southern Metals Company on August 14, continues to focus on U.S.-based industrial targets, as reported in Ransomware Group Storm Hits: Southern Metals Company.

Implications

The exploitation of edge networking devices like Fortinet firewalls represents a significant risk to supply chain integrity and critical infrastructure. The ability of RaaS affiliates to rapidly weaponize vulnerabilities means that the window for patching is narrower than ever. Furthermore, the rise of AI-driven extortion and EDR evasion techniques suggests that traditional signature-based defenses are increasingly inadequate against modern ransomware strains.

Recommendations

Encrygma analysts recommend that organizations immediately audit all Fortinet FortiOS and FortiProxy assets for unpatched vulnerabilities. Implementing robust multi-factor authentication (MFA) and network segmentation is critical to preventing lateral movement. Additionally, organizations should integrate real-time threat intelligence feeds to monitor for indicators of compromise (IoCs) associated with Gunra and Qilin. Regular testing of incident response plans and offline backup restoration is essential to mitigate the impact of double-extortion attacks.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo