Gunra ransomware group bypassing MFA and exfiltrating enterprise data via Fortinet flaws

The FBI, CISA, and South Korea’s National Police Agency issued a joint advisory Monday on Gunra ransomware, also known as Golden Community. The RaaS operation exploits two Fortinet firewall vulnerabilities, CVE-2024-55591 and CVE-2025-24472, for initial access, then runs double extortion against healthcare, financial services, and government targets worldwide.

Roman Sannikov, Global Research Coordinator, iCOUNTER

“Gunra’s exfiltration playbook is what should worry Microsoft 365 shops specifically. The advisory documents a custom executable pulling data straight out of OneDrive and SharePoint, then in at least one case moving the archived data out to Mega in volumes running into the tens of terabytes. Getting into position to do that took real infrastructure: the actors moved laterally using Impacket tools over SMB and hijacked active sessions by stealing VPN cookies, all before touching a single file. Moving that much data without tripping alerts takes real operational patience, and it fits a pattern: CISA notes the actors deliberately operate between 10pm and 6am to stay under the radar of anyone watching logs during business hours. Once they do start encrypting, it’s fast, ChaCha20 paired with RSA-4096 across a multi-threaded engine hitting multiple files at once. If your detection coverage drops off overnight, that’s exactly the gap this group, now also operating under the alias Golden Community, is built to exploit.”

These advisories are not made lightly. So organizations need to pay attention. Especially Microsoft 365 shops to avoid being pwned by these threat actors.

UPDATE: Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs had this comment: 

“Gunra made multi-factor authentication (MFA) lie for them. In the South Korean case, the group modified virtual desktop infrastructure (VDI) authentication files to accept a hardcoded attacker-chosen one-time password, and every subsequent login looked legitimate to monitoring tools. Most organizations treat MFA as the last line of defense. Gunra treated it as the first thing to subvert.

“The sector targeting is economic. Healthcare, financial services, and government can’t tolerate downtime or survive a data leak. Encrypting their systems while threatening to publish stolen records hits both pressure points at once.

“CVE-2024-55591 and CVE-2025-24472, the two Fortinet authentication bypasses that got them initial access, are eighteen months old and have been exploited by multiple ransomware groups. Patching fixes the entry point. It does nothing about an authentication backdoor already embedded in the MFA flow. I’ve seen organizations close the vulnerability and declare themselves clean while the attacker’s persistence mechanism sat untouched in the auth stack.

“The advisory also flags a recoverable flaw in Gunra’s Linux encryptor. The variant seeds its ChaCha20 keys with time() instead of a secure random number generator, so defenders who preserve file timestamps can reconstruct keys without paying. Any organization hit by the Linux variant should get forensics involved before wiring cryptocurrency.

“Gunra created a “forticloud-sync” account with super user privileges and a hardcoded password on compromised Fortinet firewalls. That account survives a firmware update, and so do modified VDI authentication files. An organization that patches and stops there is giving Gunra a head start on round two.”

John Strand, Owner, Black Hills Information Security, Inc.:

“The goal of targeting critical infrastructure is really twofold. With nation-state attacks, the objective can be straightforward. You want to create pain for your adversary. But with ransomware groups, I think there are two things we need to understand.

“First, critical infrastructure has become a dinner bell. Ransomware groups have seen how exposed and neglected some of this infrastructure is in countries like the United States, and now they’re swarming toward it because they recognize the opportunity.

“The second factor is pain. There’s been a major push in the security industry for organizations to refuse ransomware payments. But that position becomes much more complicated when an attack against critical infrastructure potentially impacts hundreds of thousands or even millions of people. It’s one thing to say you won’t pay the bad guys when the impact is contained to your organization. It’s another thing entirely when water, power, healthcare, or essential municipal services are disrupted. At that point, refusing to pay may sound principled, but elected officials also have to answer to the people whose lives are being disrupted. That creates enormous pressure to restore those services as quickly as possible.”

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading