Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, News

Gunra Ransomware: Six-Agency Advisory Targets Fortinet-Exploiting RaaS Group

What Happened

Six government agencies published joint advisory AA26-222A on August 10, warning organizations about Gunra, a double-extortion ransomware group operating a structured Ransomware-as-a-Service affiliate program. The agencies involved are the FBI, CISA, NSA, Department of Defense Cyber Crime Center, U.S. Secret Service, and South Korea’s National Police Agency.

Gunra emerged in April 2025 and is built on leaked Conti1 ransomware source code. The group operates a Tor-based ransom negotiation portal and a dedicated data leak site used to pressure organizations that refuse to pay. Affiliates negotiate ransoms, customize deployments, and split proceeds with the Gunra core group through a formalized RaaS model.

Initial access comes almost exclusively through two Fortinet authentication bypass vulnerabilities: CVE-2024-55591 and CVE-2025-24472, both affecting specific versions of FortiOS and FortiProxy. After gaining access, affiliates escalate privileges, move laterally through the network, and exfiltrate data before encrypting files to maximize leverage in ransom negotiations.

Why This Matters for Canadian Organizations

Gunra targets the sectors where Canadian organizations hold the greatest exposure: healthcare, financial services, critical manufacturing, transportation, and government. Fortinet products are deeply embedded in Canadian enterprise and government network infrastructure, making the two CVEs named in this advisory directly relevant to Canadian security teams.

For organizations subject to OSFI Guideline B-13, the Gunra advisory is an immediate operational trigger. Institutions that have not patched CVE-2024-55591 and CVE-2025-24472 in their Fortinet environments are plausible targets for RaaS affiliates actively scanning for these flaws. A successful Gunra intrusion involving personal financial data would also trigger PIPEDA breach notification obligations.

The South Korean co-signatory on the advisory confirms Gunra is not limited to North American targets. Its affiliate model means attack volume and quality vary across incidents, but the initial access method — Fortinet VPN exploitation — is consistent. Canadian organizations relying on FortiGate and FortiProxy as perimeter defenses need to verify their patch status now.

Canadian healthcare organizations face particular risk. Hospital systems, regional health authorities, and health insurance administrators represent high-value targets for double-extortion groups because they face intense pressure to restore operations quickly and hold large volumes of protected health information.

What to Do

Apply patches for CVE-2024-55591 and CVE-2025-24472 immediately if you have not done so. Verify your Fortinet firmware versions against the affected version lists in the CISA advisory and cross-reference with Fortinet’s published security bulletins.

Enforce phishing-resistant MFA on all VPN and remote access gateways. Audit network segmentation to limit lateral movement in the event of a successful intrusion. Maintain offline, immutable backups in isolated locations and test restoration procedures.

Load Gunra’s indicators of compromise into your SIEM and threat detection tools. Healthcare, financial services, and government security teams should review this advisory against their existing incident response plans and verify that their forensics and legal notification workflows are current.

Read the full advisory at CISA (AA26-222A).

Enjoy this article? Don’t forget to share.