US, South Korea warn Gunra ransomware exploits Fortinet vulnerabilities
This digest was compiled by AI from multiple sources — links to the originals are below.

US and South Korean agencies warn that Gunra ransomware is exploiting two legacy Fortinet authentication bypass vulnerabilities to breach government and critical infrastructure networks. The joint advisory, published August 10 by the FBI, CISA and South Korea's National Police Agency, details persistence and lateral movement tactics used to exfiltrate Microsoft 365 data.
Key Facts
- The advisory identifies CVE-2024-55591 and CVE-2025-24472 as the two FortiOS and FortiProxy authentication bypass vulnerabilities Gunra exploits.
- Gunra emerged from leaked Conti ransomware source code released in 2022 and was first observed in April 2025.
- In early 2026, Gunra launched a structured ransomware-as-a-service affiliate program on dark web forums and adopted the alias "Golden Community."
- In one observed case, attackers used default credentials to access an administrator account on an SSL-VPN appliance because account lockout controls were absent.
- Attackers also modified authentication processing files on a corporate VDI portal to continuously bypass multi-factor authentication.
Joint US-South Korea Advisory
The FBI, CISA and other US government agencies issued the advisory jointly with South Korea's National Police Agency on August 10. The advisory warns that Gunra ransomware targets government organizations and critical national infrastructure. Gunra operates as a ransomware-as-a-service group whose affiliates gain initial access through known vulnerabilities in internet-facing firewalls and VPN appliances. The group is based on leaked Conti ransomware source code and, in early 2026, advertised a structured RaaS affiliate program on dark web forums under the alias "Golden Community."
Fortinet Authentication Bypass Flaws
Gunra specifically targets CVE-2024-55591, a critical FortiOS and FortiProxy flaw that allows remote attackers to gain super-admin privileges through crafted requests to the Node.js websocket module. The group also targets CVE-2025-24472, a high-severity authentication bypass affecting FortiOS and FortiProxy with Security Fabric enabled, triggered by crafted CSF proxy requests when serial numbers of upstream and downstream devices are known. Patches are available for both vulnerabilities, but the FBI has observed continued exploitation of the legacy flaws. Jacob Krell, senior director at Suzu Labs, said multiple ransomware groups have exploited both flaws and victims can remain targetable even after applying fixes.
Post-Exploitation Activity
After initial access, Gunra affiliates use advanced persistence and lateral movement techniques to bypass authentication protocols and exfiltrate large volumes of Microsoft 365 data. In one observed case, attackers gained access to an SSL-VPN administrator account by exploiting default credentials where account lockout controls were absent. They then downloaded the OpenSSH tunnelling tool to connect compromised systems to an attacker-controlled server. In another case, attackers modified authentication processing files on the corporate VDI authentication portal server to continuously bypass multi-factor authentication.
1 source
US, South Korea warn Gunra ransomware exploits Fortinet vulnerabilities



