Full research report

US and South Korea warn of Gunra ransomware targeting govt agencies

Original reporting β†—
β˜… Threat intelligence assessment medium confidence

Executive assessment

The strongest verified operational fact is that both Fortinet authentication bypasses are in CISA's Known Exploited Vulnerabilities catalogue and can yield remote super-admin control. CVE-2024-55591 reaches a Node.js WebSocket path, while CVE-2025-24472 concerns Cooperative Security Fabric proxy handling and has additional configuration and knowledge prerequisites. Independent monitoring shows Gunra remained active immediately before the reported warning and had claimed victims across numerous countries and sectors. However, no accessible primary advisory tied Gunra to these CVEs, and no verified public PoC was found, so the campaign-level attribution should be treated as credible reporting rather than confirmed fact.

What happened

Reporting published on 11 August 2026 says US and South Korean authorities warned that Gunra ransomware was targeting government and critical-infrastructure organisations and using two Fortinet authentication-bypass vulnerabilities for initial access. Independent records establish that Gunra has operated since April 2025 and remained active in August 2026, while CISA separately confirms exploitation in the wild of CVE-2024-55591 and CVE-2025-24472. The specific Gunra attribution and claimed joint-government warning could not be verified from an accessible primary advisory during this investigation.

Affected scope

CVE-2024-55591 affects FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12. CVE-2025-24472 affects the same listed release ranges but requires an enabled Security Fabric and prior knowledge of upstream and downstream device serial numbers. Reported Gunra targeting spans government, critical infrastructure, healthcare, finance and other enterprises; independent leak-site monitoring also records real-estate, pharmaceutical and manufacturing victims across multiple countries.

Technical assessment

Both CVEs cross an authentication boundary and can provide remote super-admin privileges. CVE-2024-55591 involves crafted requests reaching a Node.js WebSocket component, whereas CVE-2025-24472 involves crafted Cooperative Security Fabric proxy requests under more restrictive environmental preconditions. Administrative compromise of an internet-facing security appliance is a significant initial-access opportunity, but the accessible evidence does not establish which victims were compromised through each flaw or provide a verified end-to-end Gunra intrusion chain.

Recommended defensive actions

  1. Immediately patch affected FortiOS and FortiProxy appliances to a Fortinet-supported release outside the affected ranges and validate the exact target release against the current vendor advisory.
  2. Inventory all internet-facing Fortinet appliances and verify their FortiOS or FortiProxy versions, Security Fabric configuration and management-interface exposure.
  3. Restrict administrative access to trusted management networks and disable unnecessary internet exposure of administrative services.
  4. Audit appliance configuration changes, administrator creation and unexpected privileged sessions for evidence of compromise rather than treating patching alone as sufficient.
  5. Segment perimeter appliances from internal management and critical systems to limit lateral movement after administrative compromise.
  6. Test offline, immutable backups and incident-recovery procedures for systems reachable from affected network boundaries.

Uncertainties and evidence gaps

  • The cited US–South Korean joint advisory was not located on an accessible primary government page, so its wording, issuing bodies and publication date remain independently unverified.
  • CISA confirms exploitation of both CVEs generally, but the accessible CISA and NVD records do not attribute that exploitation specifically to Gunra.
  • The reported Golden Community alias, formal ransomware-as-a-service programme and relationship with Lazarus Group were not independently verified.
  • No verified public proof-of-concept or exploit repository was identified during the focused review.
  • Victim counts and sector data from leak-site monitoring are based partly on criminal claims and do not independently prove successful encryption or data theft.

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessRemote network reachability to an affected FortiOS or FortiProxy service; CVE-2025-24472 additionally depends on Security Fabric being enabled and knowledge of relevant device serial numbers.
ComponentFortiOS or FortiProxy administrative authentication boundary, including the Node.js WebSocket module or Cooperative Security Fabric proxy handling.
MechanismCrafted requests can bypass normal authentication and confer super-admin privileges.
ImpactAn attacker can obtain privileged control of a perimeter security appliance, enabling configuration tampering and potential access to protected networks.
DetectionReview administrative logins, newly created or modified administrator accounts, unexpected configuration changes, WebSocket or Security Fabric proxy activity, and privileged sessions originating from untrusted addresses.
MitigationApply Fortinet-supported fixed releases outside the affected ranges, follow CISA and vendor mitigation instructions, restrict management exposure, or discontinue affected products where remediation is unavailable.
Exploitation status

CISA confirms both vulnerabilities were exploited in the wild, but the available primary records do not independently confirm their attribution to current Gunra attacks; no verified public PoC was found.

The investigation first attempted to validate the reported 11 August warning, then separated that campaign claim from the independently verifiable Fortinet vulnerabilities. NVD and CISA records confirmed the affected products, mechanisms and exploitation status of both CVEs, while ransomware-leak monitoring independently supported Gunra's continuing activity and broad geographic reach. The evidence therefore supports an urgent Fortinet remediation requirement and the existence of an active Gunra operation, but not a high-confidence attribution of these particular vulnerabilities to Gunra without the underlying joint advisory.

  1. Does the supplied news page support the claimed joint warning and Gunra campaign details?
    Opened the supplied BleepingComputer article URL.
    bleepingcomputer.com β†—

    The site returned a security-verification page, preventing independent review of the published article.

    why The supplied article text remained untrusted reporting and could not serve as verified proof of the government warning.

  2. What is CVE-2024-55591 and which releases are affected?
    Reviewed the National Vulnerability Database record.
    nvd.nist.gov β†—

    NVD describes a remote authentication bypass affecting FortiOS 7.0.0–7.0.16 and FortiProxy 7.0.0–7.0.19 and 7.2.0–7.2.12, allowing super-admin access through crafted requests to a Node.js WebSocket module.

    why This confirmed the first CVE's product scope and security impact independently of the campaign reporting.

  3. What is CVE-2025-24472 and how does it differ?
    Reviewed the National Vulnerability Database record.
    nvd.nist.gov β†—

    NVD describes an authentication bypass affecting the same listed release ranges, with Security Fabric and device-serial-number preconditions, through crafted CSF proxy requests.

    why The record established that the second flaw is related but has materially different exploitation prerequisites.

  4. Is exploitation of CVE-2024-55591 confirmed?
    Opened the filtered CISA Known Exploited Vulnerabilities catalogue entry.
    cisa.gov β†—

    CISA lists the flaw as exploited in the wild, added it on 14 January 2025 and directs organisations to apply vendor mitigations or discontinue use.

    why This supports prioritised remediation, but the entry does not identify Gunra as the exploiting actor.

  5. Is exploitation of CVE-2025-24472 confirmed?
    Opened the filtered CISA Known Exploited Vulnerabilities catalogue entry.
    cisa.gov β†—

    CISA lists the flaw as exploited in the wild, added it on 18 March 2025 and directs organisations to follow vendor and applicable federal guidance.

    why This confirms real-world exploitation independently of probability scores, while leaving campaign attribution unresolved.

  6. Does Fortinet provide a directly reviewable advisory and fixed-version guidance?
    Attempted to open Fortinet PSIRT advisory FG-IR-24-535 referenced by NVD.
    fortiguard.fortinet.com β†—

    The Fortinet site blocked access to the requested page in this review.

    why Exact fixed-version guidance could not be verified directly, so remediation is stated conservatively as moving to a supported release outside the confirmed affected ranges and checking the current vendor advisory.

  7. Is there independent evidence that Gunra exists and remained operational near the reported warning date?
    Reviewed the Ransomware.live Gunra group record.
    ransomware.live β†—

    The record identifies Gunra as active since April 2025, tracks Windows and Linux activity, and lists 51 claimed victims across 27 countries with the latest observed victim dated 5 August 2026.

    why This corroborates Gunra's existence and continuing activity but does not prove the government-warning details or Fortinet exploit attribution.

ActorsGunra
MalwareGunra ransomware
Targetsgovernment organisationscritical-infrastructure organisationshealthcare and public-health organisationsfinancial-services organisationsreal-estate organisationspharmaceutical organisationsmanufacturing organisations

Research coverage

All 68 registered source leaves were evaluated for this run: 61 completed, 0 were unavailable, 0 failed and 7 were disabled. For this story, 18 registered sources supplied useful evidence (3 primary, 13 corroborating, 2 contextual and 0 PoC/exploit references). 43 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked β€” no match Unavailable Failed Disabled
Complete source-by-source audit 68 sources
SourceRun resultValueWhy it was useful β€” or not
BleepingComputernews ok15 records Primary evidence1 matched items Published the source report used to frame and date the event.
CISA KEVkev ok1665 records Primary evidence4 matched items Confirmed that a related CVE is listed in CISA's Known Exploited Vulnerabilities catalogue. Supplied a vendor or government advisory opened and verified during focused research.
NVDcve ok900 records Primary evidence2 matched items Supplied a vendor or government advisory opened and verified during focused research.
CISA Alertsnews ok empty0 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI Discorddeepdarkcti ok7 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI exploitsdeepdarkcti ok24 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI forumsdeepdarkcti ok264 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI malware samplesdeepdarkcti ok3 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI marketsdeepdarkcti ok127 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI phishingdeepdarkcti ok19 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI ransomware gangsdeepdarkcti ok680 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI RATsdeepdarkcti ok1 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1008 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Context2 matched items Provided lower-confidence OSINT context matched to an explicit CVE.
FIRST EPSSepss ok Context2 matched items Added exploitation-probability context; EPSS does not itself prove exploitation.
AlienVault OTXdark_web ok10 records Checked β€” no match The source completed, but none of its retained records matched this story.
CIRCL CVEcve ok30 records Checked β€” no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5323 records Checked β€” no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok1 records Checked β€” no match The source completed, but none of its retained records matched this story.
DNSDumpster domain IOC enrichmentresearch ok1 records Checked β€” no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
Fortinet PSIRTvendor_advisory disabled Disabled1 matched items Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
GitHub topic: pocresearch ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
GreyNoiseexploit_reference ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok1 records Checked β€” no match The source completed, but none of its retained records matched this story.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok10 records Checked β€” no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked β€” no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok12 records Checked β€” no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok20 records Checked β€” no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok20 records Checked β€” no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked β€” no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok20 records Checked β€” no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok14 records Checked β€” no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok20 records Checked β€” no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1590 records Checked β€” no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
MISP Galaxyresearch ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
MISP threat actor galaxyactor ok0 records Checked β€” no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked β€” no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
Rapid7news ok3 records Checked β€” no match The source completed, but none of its retained records matched this story.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok1 records Checked β€” no match The source completed, but none of its retained records matched this story.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
Shodanresearch ok7 records Checked β€” no match The source completed, but none of its retained records matched this story.
Sigma Rulesresearch ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
Sophos IOCsresearch ok1 records Checked β€” no match The source completed, but none of its retained records matched this story.
The Hacker Newsnews ok15 records Checked β€” no match The source completed, but none of its retained records matched this story.
ThreatFoxthreat_intelligence ok100 records Checked β€” no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok1 records Checked β€” no match The source completed, but none of its retained records matched this story.
Unit42 IOCsresearch ok empty0 records Checked β€” no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked β€” no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok4 records Checked β€” no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked β€” no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked β€” no match The source completed, but none of its retained records matched this story.
Additional verified pages 24 opened outside the registered collection
Vulnerability & exploitation4
CVE-2025-24472 CISA KEV Fortinet FortiOS and FortiProxy Β· added 2025-03-18 Β· used in ransomware CISA catalog β†—
CVE-2024-55591 CISA KEV Fortinet FortiOS and FortiProxy Β· added 2025-01-14 Β· used in ransomware CISA catalog β†—
CVE-2024-55591 EPSS 98.3% 100th percentile exploitation probability
CVE-2025-24472 EPSS 3.3% 88th percentile exploitation probability
OSINT / dark-web chatter2
deepdarkCTI: CVE-2024-55591 (Fortinet) raw.githubusercontent.com β†—
deepdarkCTI: CVE-2025-24472 (Fortinet) raw.githubusercontent.com β†—
Vendor & gov advisories4
CISA Known Exploited Vulnerabilities entry for CVE-2024-55591 cisa.gov β†—

Confirms exploitation of the FortiOS and FortiProxy authentication bypass and directs organisations to apply vendor mitigations.

CISA Known Exploited Vulnerabilities entry for CVE-2025-24472 cisa.gov β†—

Confirms exploitation of the Security Fabric authentication bypass and gives a remediation requirement.

NVD record for CVE-2024-55591 nvd.nist.gov β†—

Defines the affected versions, remote authentication-bypass mechanism and resulting super-admin access.

NVD record for CVE-2025-24472 nvd.nist.gov β†—

Defines the Security Fabric preconditions, affected versions and super-admin impact.

OSINT / dark-web chatter1
Ransomware.live Gunra group record ransomware.live β†—

Tracks Gunra as active from April 2025 and records 51 claimed victims across 27 countries as of 12 August 2026.