
Gunra Ransomware Exploits Fortinet Vulnerabilities in Global Campaign Against Critical Infrastructure
US and South Korean agencies warn of Gunra ransomware, a Conti-derived RaaS variant exploiting FortiOS flaws to target critical infrastructure via double-extortion tactics.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- CISA / FBI / South Korea National Police Agency
- Read Time:
- 5 min
Executive Summary
On August 12, 2026, a joint cybersecurity advisory was released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and South Korea’s National Police Agency (NPA) regarding the Gunra ransomware group. This threat actor has rapidly evolved into a sophisticated Ransomware-as-a-Service (RaaS) operation, specifically targeting government agencies and critical infrastructure sectors globally. The group utilizes a double-extortion model, where data is both encrypted and exfiltrated to a dedicated leak site (DLS) to maximize leverage during ransom negotiations. The advisory highlights a significant surge in Gunra activity over the last 48 hours, coinciding with reports of major disruptions at Ceva Logistics and data breaches affecting South Korean media platforms.
Threat Analysis
Gunra emerged in early 2025 as a niche variant but has expanded its footprint in 2026 by adopting a RaaS business model. The group’s core codebase is heavily derived from the leaked Conti ransomware source code, providing it with a mature foundation for high-speed encryption and network propagation. By recruiting specialized affiliates, Gunra has diversified its targeting, moving beyond simple commercial targets to high-value critical infrastructure. The group’s recent campaigns demonstrate a high degree of operational security and a preference for exploiting internet-facing vulnerabilities in edge security devices, allowing for rapid initial access without the need for complex phishing campaigns. This shift reflects a broader 2026 trend where ransomware groups automate the exploitation of N-day vulnerabilities to achieve scale.
Technical Details
The current campaign primarily exploits known vulnerabilities in Fortinet FortiOS and FortiProxy systems. Once an edge device is compromised, Gunra actors deploy customized payloads designed to bypass modern security stacks. A notable technical advancement in the latest Gunra samples is the inclusion of sophisticated EDR-evasion modules. These modules utilize direct system calls and hook-removal techniques to blind Endpoint Detection and Response (EDR) tools, a trend also observed in other 2026 groups like 'The Gentlemen.' For lateral movement, the group relies on a combination of Cobalt Strike, Mimikatz, and 'Living off the Land' (LotL) binaries to minimize their forensic footprint. The encryption phase employs a multi-threaded implementation of AES-256-GCM, with file keys protected by a unique RSA-4096 master key for each victim, ensuring that data recovery without the private key is computationally infeasible.
Attribution Assessment
Intelligence agencies attribute Gunra to a decentralized network of cybercriminals, likely including former members of the Conti and TrickBot syndicates. The group’s infrastructure is geographically distributed, utilizing Tor-based command-and-control (C2) servers and customized negotiation portals. While the group’s origins appear to be Eastern European, the recent joint advisory from South Korean and U.S. authorities suggests a global affiliate base, including actors capable of conducting highly targeted operations against specific regional infrastructures. The use of the Conti source code suggests a shared heritage with several other high-profile RaaS groups active in 2026, indicating a consolidation of technical resources within the cybercriminal underground.
Implications
The escalation of Gunra’s activities poses a severe risk to public safety and economic stability. The recent disruption of Ceva Logistics (August 12) illustrates the group’s ability to impact global supply chains, while the breach of 3Pro TV in Seoul highlights the vulnerability of large-scale consumer data repositories. The double-extortion tactic places organizations in a precarious position where even successful data recovery does not mitigate the risk of regulatory fines and reputational damage resulting from data leaks. The targeting of municipal services, such as the City of McMinnville, further demonstrates the group’s willingness to disrupt essential public functions to force payment.
Recommendations
Encrygma recommends that all organizations immediately audit their external-facing infrastructure for unpatched Fortinet devices and apply the latest security updates. Implementing a 'Zero Trust' architecture and enforcing phishing-resistant multi-factor authentication (MFA) are essential steps to prevent lateral movement. Security teams should also enhance monitoring for EDR-tampering events and maintain immutable, offline backups of all critical data. Finally, participating in threat intelligence sharing communities is vital for staying ahead of the rapidly evolving RaaS landscape and identifying Gunra-specific indicators of compromise (IOCs) before they result in a full-scale breach.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

ThreeAM and Morpheus Ransomware Groups Launch Coordinated Global Extortion Campaigns

Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors

