Gunra Shifts Ransomware to Perimeter Break-ins

U.S. and South Korean agencies said Gunra ransomware is actively exploiting Fortinet FortiOS/FortiProxy flaws CVE-2024-55591 and CVE-2025-24472, plus Schneider Electric PowerLogic P5 CVE-2024-5559, to get into healthcare, finance, government, and critical-infrastructure networks. The same alert says the Conti-derived group has also formalized a Dark Web affiliate program, turning a Spring 2025 brand into a broader ransomware-as-a-service operation. The entry path matters: Gunra is not starting with phishing and endpoint malware. It is abusing exposed firewalls, VPNs, and industrial appliances on their public interfaces, where the bugs can hand over admin-level control or bypass authentication, so the first compromise can land at the perimeter or even near OT/ICS gear before any workstation is touched. For organizations that use those devices as the front gate to internal systems, the lasting exposure is the network behind them. Once an internet-facing appliance falls, the blast radius can quickly extend from a single box to the environment it controls, with double extortion layered on top.

Part of the PlainSec briefing for 2026-08-12

Every edition of this story: Gunra Shifts Ransomware to Perimeter Break-ins

Sources