Gunra Ransomware Targeting Critical Infrastructure: What Website and Hosting Operators Should Know

US federal agencies warn that Gunra ransomware affiliates are exploiting Fortinet vulnerabilities to break into critical infrastructure networks, steal data, and encrypt systems.

Gunra Ransomware Targeting Critical Infrastructure: What Website and Hosting Operators Should Know

United States cyber authorities have published a coordinated advisory warning that Gunra ransomware is actively exploiting known security flaws in internet-facing appliances to breach organizations that operate critical infrastructure. The joint guidance, issued by CISA, the FBI, the NSA, the US Secret Service, and partner agencies in South Korea, confirms that affiliates working under the Gunra brand are breaking into healthcare providers, financial firms, government offices, and other essential services using credential bypass bugs against Fortinet gear.

For website owners, hosting customers, developers, and agency teams, the advisory matters because the same Fortinet appliances that protect corporate networks and data centers are commonly deployed in front of hosted applications and remote admin surfaces. When an attacker walks past an unpatched perimeter device, every workload behind it becomes a potential target, including WordPress installations, virtual machines, and internal admin portals.

Key Takeaways

  • Gunra operates as a ransomware-as-a-service program, with affiliates renting access to a locker family first observed in April 2025.
  • The active intrusion path relies on two Fortinet authentication bypass flaws, CVE-2024-55591 and CVE-2025-24472, which allow administrative access without valid credentials.
  • Both Windows and Linux variants now exist; the Linux build can run up to 100 encryption threads in parallel and supports partial file encryption.
  • Attacks follow a double-extortion pattern: data is stolen before encryption, then victims are given roughly five to seven days to negotiate through a Tor-based portal before leaks are published.
  • Federal guidance emphasizes patching internet-facing systems, hardening VPN and RDP access with multifactor authentication, segmenting networks, and keeping offline immutable backups.

Who Is Behind Gunra and Why It Matters

Trend Micro first documented Gunra in April 2025, noting that the initial Windows strain reused code fragments and tradecraft borrowed from the now-defunct Conti ransomware operation. Within months, researchers identified a Linux variant, which widened the pool of servers and containers the gang could scramble. That Linux variant can launch up to 100 parallel encryption threads, store RSA-wrapped keys in separate keystore files, and partially encrypt files so that a configurable percentage of every target file is scrambled rather than the full payload.

The administrative structure is the bigger reason the family deserves attention. Under the ransomware-as-a-service model, the Gunra developers maintain the encryption tooling, payment infrastructure, and leak site, while independent affiliates carry out the intrusions. That division of labor makes the threat scalable: a single affiliate who lands a working exploit can monetize access through the central brand, and the developers keep iterating on the locker while affiliates keep finding victims.

How the Fortinet Exploits Open the Door

The current intrusion wave leans on two chained Fortinet vulnerabilities that researchers disclosed earlier. CVE-2024-55591 and CVE-2025-24472 are authentication bypass weaknesses in FortiOS and FortiProxy, the operating systems that power Fortinet firewalls and secure web gateways. When an appliance exposed to the internet is left unpatched, an attacker can send crafted requests that convince the management plane to issue an administrative session without supplying valid credentials.

With that foothold, the affiliate can create new admin accounts, change policies, pivot into internal networks, and locate the data worth stealing. Because the entry point is a perimeter appliance, the breach often looks like ordinary management traffic from the perspective of downstream servers, which is why federal agencies stress applying vendor patches before attackers reach the device.

Who Is Being Hit and Where

According to the advisory, confirmed intrusions span healthcare, financial services, professional and legal services, nonprofits, and government entities. Trend Micro reports observed activity in Turkey, Taiwan, the United States, and South Korea, while the group's own leak site lists claimed victims in Brazil, Japan, and Canada as well, including manufacturers, IT companies, and law firms. The wide sectoral and geographic spread reflects how ransomware affiliates choose targets based on exposed infrastructure rather than industry preference.

IndicatorObserved Detail
Initial observation dateApril 2025, by Trend Micro
Platform supportWindows systems, with a Linux variant added later
Encryption capacity (Linux)Up to 100 parallel encryption threads, partial file encryption supported
Business modelRansomware-as-a-service, with independent affiliates
Confirmed exploited flawsCVE-2024-55591 and CVE-2025-24472 in FortiOS and FortiProxy
Reported victim regionsTurkey, Taiwan, US, South Korea, Brazil, Japan, Canada

Defending Against Gunra Ransomware Critical Infrastructure Attacks

The federal advisory reduces the defensive checklist to a short list of high-leverage actions, and each one closes a specific gap that Gunra affiliates have been observed using.

  • Patch internet-facing appliances quickly, with priority on FortiOS and FortiProxy devices running builds vulnerable to CVE-2024-55591 or CVE-2025-24472.
  • Require multifactor authentication on every VPN tunnel and Remote Desktop Protocol listener that exposes management access.
  • Disable management interfaces on perimeter gear when they are not strictly required, and restrict them to trusted management subnets.
  • Segment the network so that a compromise of a perimeter device does not automatically grant access to production databases, WordPress admin panels, or container orchestration hosts.
  • Maintain offline or immutable backups that an attacker with administrative access cannot rewrite, encrypt, or delete.
  • Audit admin accounts on firewalls, proxies, and servers for any new local users created during the patch window.

Hosting customers and small agencies rarely run their own Fortinet appliances, but their providers may. Asking a managed hosting partner which vendor firmware versions are running on the perimeter that fronts your environment, and how often those builds are patched, is a reasonable due-diligence step during a Gunra ransomware critical infrastructure incident cycle. For teams running self-managed stacks, the same FortiOS patch warning applies directly to any in-house FortiGate or FortiProxy unit.

Why This Advisory Should Change Your Priorities

CISA's acting executive assistant director for cybersecurity, Chris Butera, framed Gunra as another indicator of the continuing pattern of disruptive ransomware incidents that affect both US and international organizations. The operational message is clear: even a well-run backup regime cannot undo the reputational and regulatory damage of stolen customer data appearing on a leak site.

Two features of Gunra make early containment especially valuable. The double-extortion playbook means data theft happens before encryption, so the moment an attacker gains administrative access is also the moment a data exposure clock starts. The Tor-based negotiation portal gives victims only about five to seven days before the leak site publishes stolen material, leaving a narrow window for legal counsel, cyber insurance carriers, and incident-response vendors to coordinate. Patching the Fortinet flaws early removes the cheapest and most reliable path affiliates have to reach that point.

Frequently Asked Questions

What is Gunra ransomware and when was it first seen?

Gunra is a ransomware family first documented by Trend Micro in April 2025. It started as a Windows-targeting locker that reused elements from the older Conti operation, and a Linux variant was added later, broadening the range of servers and containers the group can encrypt.

Which vulnerabilities does Gunra ransomware use against critical infrastructure targets?

Federal agencies say affiliates are exploiting CVE-2024-55591 and CVE-2025-24472, both authentication bypass flaws in Fortinet FortiOS and FortiProxy. When an unpatched appliance is exposed to the internet, those flaws let the attacker create an administrative session without supplying valid credentials.

How does the double-extortion part of the attack work?

Before any files are scrambled, affiliates exfiltrate sensitive data and store it off-network. Encryption then begins across the compromised environment, and the victim is directed to a Tor-based negotiation portal. Operators typically allow five to seven days before publishing the stolen data if payment is not made.

Which sectors and regions have been affected so far?

The advisory names healthcare, financial services, government, professional services, and nonprofits as observed victim categories. Trend Micro reports confirmed activity in Turkey, Taiwan, the United States, and South Korea, while the group's leak site also lists claimed victims in Brazil, Japan, and Canada.

What is the fastest way to reduce exposure to Gunra ransomware?

Apply Fortinet patches for CVE-2024-55591 and CVE-2025-24472 immediately on any internet-facing device, enforce multifactor authentication on VPN and RDP endpoints, segment internal networks, audit administrative accounts for unfamiliar users, and keep verified offline or immutable backups so encrypted data can be restored without paying the ransom.

Conclusion

Gunra ransomware critical infrastructure intrusions are arriving through perimeter appliances that many organizations treat as set-and-forget infrastructure. The most effective response is also the most mundane: patch the Fortinet flaws the advisory names, lock down every path into management interfaces, segment what attackers can reach from a perimeter foothold, and verify that backups can actually be restored. For teams that outsource their edge, the next conversation with a managed hosting partner should focus on firmware currency on the devices that sit in front of your workloads. Readiness measured before the next advisory will outperform scrambling during one, especially when the negotiation window is measured in days.