Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA and Steal Enterprise Data
Brief
A joint cybersecurity advisory from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U. S.
Secret Service, and South Korea’s National Police Agency has exposed a dangerous new wave of attacks by the Gunra ransomware group , which is actively exploiting known Fortinet VPN vulnerabilities to bypass multi-factor authentication and exfiltrate sensitive enterprise data before locking down victim networks.
Gunra first surfaced in April 2025 as a double-extortion ransomware strain believed to be built on leaked Conti source code. By early 2026, the group had matured into a full ransomware-as-a-service operation, offering affiliates a management panel, a configurable ransomware builder, and cross-platform locker payloads through dark web forums.
