Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Gunra Ransomware Gang Turns Fortinet VPN Bugs Into a Backdoor Around MFA
Gunra Ransomware Gang Turns Fortinet VPN Bugs Into a Backdoor Around MFA
Read Time:3 Minute, 20 Second

U.S. and South Korean authorities have jointly warned that the Gunra ransomware group is actively breaking into corporate networks by exploiting long-known authentication bypass flaws in Fortinet VPN and firewall appliances, then using that foothold to strip away multi-factor authentication protections entirely. The advisory, issued by the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s National Police Agency, paints a picture of a ransomware operation that has matured rapidly since it first appeared in the wild.

From New Arrival to Full RaaS Operation

Gunra emerged in April 2025 as a double-extortion ransomware strain reportedly built on source code leaked from the Conti operation. In under a year, it evolved into a complete ransomware-as-a-service platform, complete with an affiliate management panel, a configurable payload builder, and lockers capable of running across multiple operating systems. Investigators also observed the crew operating under a second name, Golden Community, while actively recruiting penetration testers and other technically skilled operators to serve as initial access brokers in exchange for a share of ransom payments.

Turning VPN Flaws Into an MFA Bypass

The advisory’s most alarming detail is how Gunra affiliates get past multi-factor authentication rather than around it entirely. Investigators traced initial access to two previously disclosed authentication bypass bugs in specific FortiOS and FortiProxy builds. In one confirmed intrusion, attackers combined a poorly protected SSL-VPN admin account, which had default credentials and no lockout policy, with tampered authentication files on a corporate virtual desktop portal. The modification ensured that a one-time password value chosen by the attackers would always be accepted as valid, effectively neutralizing MFA rather than defeating it through brute force or phishing.

Moving Through the Network

Once inside, Gunra affiliates lean on well-known post-exploitation tooling rather than custom malware for lateral movement. The advisory describes heavy use of Impacket utilities to move over SMB and pull credentials directly from domain controllers, enabling both pass-the-hash and pass-the-ticket techniques. In some cases, the group intercepted VPN session traffic to hijack active user sessions outright, and in at least one incident stole a symmetric key from an access control server that let them mass-decrypt stored enterprise passwords.

Data Theft Before the Encryption Hits

True to the double-extortion playbook, Gunra prioritizes stealing data before locking anything down. A custom exfiltration tool tracked as main.exe has been used to pull files out of Microsoft OneDrive and SharePoint environments, with stolen archives, sometimes reaching into the tens of terabytes, routed to the file-sharing service Mega. Common open-source tools including 7-Zip, RClone, and FileZilla support the compression and transfer process. When the encryptor finally runs, it combines ChaCha20 and RSA-4096 across a multi-threaded design, appends the .ENCRT extension to affected files, and drops a ransom note named R3ADM3.txt in every folder it touches. Victims are typically pointed to a Tor negotiation site or the qTox messaging app and given roughly five to seven days before the group threatens to leak or sell the stolen data.

What Defenders Should Do Now

Because the entire intrusion chain hinges on unpatched, internet-facing VPN infrastructure, the advisory’s core recommendation is straightforward but urgent:

  • Patch FortiOS and FortiProxy devices against the specific authentication bypass vulnerabilities cited in the advisory without delay.
  • Enforce account lockout policies and eliminate default credentials on all VPN and SSL-VPN administrative accounts.
  • Monitor for anomalous authentication files or configuration changes on VDI and remote-access portals.
  • Watch for known post-exploitation tooling such as Impacket scripts, RClone, and large outbound transfers to file-sharing services.
  • Treat MFA as one layer, not a guarantee — session hijacking and authentication-file tampering can render it moot if the underlying infrastructure is vulnerable.

With Gunra actively recruiting affiliates and expanding its toolset, organizations still running unpatched Fortinet appliances should treat this advisory as a near-term warning rather than routine guidance.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Gunra Ransomware Gang Turns Fortinet VPN Bugs Into a Backdoor Around MFA, use the discussion on Forum.

>> forum community

Comments

Leave a Reply