Gunra Ransomware Exploits Fortinet and Schneider Electric Vulnerabilities

Cybersecurity agencies from South Korea and the United States have issued warnings about the Gunra ransomware, which is actively targeting critical infrastructure sectors worldwide. Affected industries include healthcare, financial services, government facilities, and nonprofit organizations.

Gunra ransomware operators exploit vulnerabilities in internet-facing Schneider Electric PowerLogic P5 devices (CVE-2024-5559) and Fortinet FortiOS and FortiProxy appliances (CVE-2025-24472) to gain initial access to networks. Once inside, they deploy the ransomware, employing a double extortion tactic that involves both data exfiltration and encryption. Victims who do not comply with ransom demands within five to seven days risk having their data published on leak sites.

Since its emergence in April 2025, Gunra has listed 51 victims, predominantly in South Korea, Brazil, Spain, Thailand, and Hong Kong. Notably, most targets are located in Australia, East Asia, and Europe, with only three reported victims in Canada and the U.S.

The group primarily uses phishing attacks to deliver malicious payloads and conducts negotiations through a WhatsApp-themed chat panel. They are capable of encrypting large files rapidly by utilizing advanced stream cipher encryption methods like Salsa20 or ChaCha20.

In January 2026, Gunra launched a formal Ransomware-as-a-Service (RaaS) affiliate program on dark web forums, providing affiliates with access to a management panel, configurable ransomware builders, cross-platform locker payloads, and comprehensive documentation. Both Windows and Linux variants of the ransomware are available, although a March 2026 analysis identified a significant cryptographic weakness in the Linux version, allowing for potential decryption of affected files.

The U.S. Federal Bureau of Investigation (FBI) has observed Gunra adopting new branding aliases, such as Golden Community, to expand its operations. The group is also recruiting penetration testers and ethical hackers as initial access brokers, offering them a share of ransom profits in exchange for network access.

Attackers utilize Impacket libraries like “psexec.py” and “smbclient.py” for lateral movement within networks via the Server Message Block (SMB) protocol. They also employ “secretsdump.py” to extract password hashes from compromised domain controllers. To conceal their activities, the group deletes system and network access logs, clears command histories, and primarily operates between 10 p.m. and 6 a.m. Data exfiltration from Microsoft OneDrive and SharePoint is conducted using an executable named “main.exe.”

Organizations are urged to promptly apply patches for the identified vulnerabilities and enhance their security measures to mitigate the risk posed by Gunra ransomware. This includes implementing robust phishing defenses, monitoring for unusual network activity, and maintaining up-to-date backups to ensure data recovery in the event of an attack.