Skip to content
Flash Briefing critical HealthcareFinanceGovernmentCritical Infrastructure

Gunra Ransomware: Five-Agency Advisory Flags Fortinet-Backed RaaS Targeting Healthcare and Critical Infrastructure

A joint advisory issued on 11 August 2026 by CISA, the FBI, NSA, US Secret Service, and South Korea’s National Police Agency designates Gunra as an active ransomware-as-a-service threat targeting hospitals, government agencies, and financial institutions across the US, South Korea, and Europe. The five-agency advisory — numbered AA26-222A under the #StopRansomware programme — attributes at least 51 confirmed attacks to Gunra affiliates since the group transitioned to a formal RaaS model earlier in 2026.

The designation carries particular weight given the breadth of co-signatories. Joint Korean-US advisories have historically preceded or accompanied law enforcement action, and the inclusion of the NSA signals concern about Gunra’s targeting of national security-adjacent infrastructure.

Origins and ransomware lineage

Gunra first appeared in April 2025 as a private operation. Technical analysis of its encryptor codebase indicates a clear Conti lineage — shared locker logic, overlapping configuration formats, and similar directory traversal logic — consistent with the pattern seen across multiple post-Conti successor groups that have emerged since the Conti source code leaked in 2022. The group opened affiliate recruitment in early 2026, adopting the standard RaaS model: affiliates conduct intrusions and deploy ransomware in exchange for a revenue share, while the core team maintains the malware, ransom negotiation infrastructure, and data leak site.

The double extortion model is in full effect. Victims are encrypted and simultaneously threatened with publication to Gunra’s dedicated leak site if ransom is not paid within the affiliate’s stated deadline. The advisory notes that payment has not consistently resulted in decryption key delivery.

Initial access: two Fortinet flaws

Gunra affiliates rely primarily on two Fortinet authentication bypass vulnerabilities for network entry: CVE-2024-55591 and CVE-2025-24472. Both affect FortiOS and FortiProxy in the SSL VPN and web management interfaces, allowing an unauthenticated attacker to gain super-admin privileges or create rogue administrative accounts. While patches for both flaws have been available for some time, the advisory confirms that a substantial proportion of victim environments had unpatched perimeter devices at the time of compromise.

Post-access TTPs follow a now-familiar pattern: persistence via modified admin accounts and scheduled tasks, internal reconnaissance using built-in Windows tooling and Bloodhound for Active Directory mapping, lateral movement via RDP and SMB, data staging and exfiltration, and finally ransomware deployment. The advisory notes that affiliates have demonstrated patience — dwelling in networks for up to three weeks before encryption, prioritising data exfiltration completeness over speed.

A critical caveat for Linux victims

Threat intelligence firm Breakglass Intelligence published findings alongside the advisory that bear on victim response: Gunra’s Linux encryptor contains a fatal cryptographic implementation flaw that renders encrypted files recoverable without the decryptor. This applies specifically to Linux-targeted deployments — the Windows variant does not share the flaw. Organisations with Linux systems encrypted by Gunra should engage specialist incident response before making any ransom payment decision. Paying for a Linux decryptor may be entirely unnecessary.

Patch priority: Confirm FortiOS and FortiProxy patch status against both CVE-2024-55591 and CVE-2025-24472. Any internet-exposed Fortinet device should be treated as potentially pre-compromised if these patches were not applied promptly after their respective disclosure dates.

Audit administrative accounts: Review FortiGate, FortiProxy, and downstream domain administrative accounts for unfamiliar entries. Gunra affiliates create persistent admin accounts as a fallback access mechanism; these may survive firewall patching if not actively hunted.

Healthcare-specific posture: The advisory identifies healthcare as the highest-frequency targeted sector. Hospitals and health systems running unpatched Fortinet perimeter devices should treat the past 90 days as a potential exposure window and initiate log review accordingly.

Linux recovery: Before authorising any ransom payment involving Linux-encrypted systems, consult the Breakglass Intelligence findings or engage an IR firm with access to the decryption research. The flaw may make payment unnecessary.

The scale and breadth of Gunra’s targeting — crossing healthcare, government, and financial sectors simultaneously, across two continents — reflects the operational maturity of a well-resourced RaaS operation. The joint advisory and Korean co-signature suggest that law enforcement attention is already focused on the group’s infrastructure.