Ransomware & Extortion · Ransomware

Gunra RaaS Turns Edge Access Into Extortion

U.S. and South Korean agencies on Monday warned about Gunra, an emerging ransomware group that has grown into a ransomware-as-a-service operation and has been linked to victims across multiple sectors worldwide. The advisory says Gunra first surfaced in April 2025 and by early 2026 was recruiting outside hackers to help it break into networks.

The group does not rely only on the ransomware itself. It buys or recruits initial access, then uses known vulnerabilities in internet-facing devices such as VPN gateways, firewalls, and RDP-exposed systems to get a foothold, after which it can push double extortion through a Tor-based negotiation site and leak site. That means the exposed edge device is often the real entry point, and cleanup has to account for the access path as well as the encryptor.

For defenders, the important map point is where Gunra starts: organizations with reachable remote-access or perimeter gear are in the same exposure class even if the ransomware never lands through a phishing email or a payload download. In that setup, the gateway can become the doorway to broader network compromise and data theft pressure.

4 sources · Aug 11

CVE-2024-55591

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0… Known ransomware campaign use. EPSS 94% (100th percentile).

CISA federal remediation date Jan 21 · date passed

CVE-2025-24472

NVD KEV

Known exploited · CISA KEV

CVSS 8.1 HIGH: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through… Known ransomware campaign use. EPSS 7% (94th percentile).

CISA federal remediation date Apr 8 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-08-10

Every edition of this story: Gunra RaaS Turns Edge Access Into Extortion