Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Fortinet Firewall Exploits Jump 12% as Gunra Pivots to RaaSRegulations & Laws
4 min readFor Compliance Officers

Fortinet Firewall Exploits Jump 12% as Gunra Pivots to RaaS

What Changed

The FBI and South Korea's National Policy Agency issued a joint advisory in May 2026, highlighting a significant shift in ransomware dynamics. Gunra, which surfaced in April 2025 using leaked Conti source code, has transitioned to a ransomware-as-a-service (RaaS) platform by January 2026. The group now recruits initial access brokers on cybercriminal forums, operates under multiple aliases including "Golden Community," and exploits CVE-2024-55591 and CVE-2025-24472 in Fortinet firewalls to target healthcare, financial services, and government sectors globally.

Dragos reported 1,140 ransomware incidents affecting industrial organizations worldwide in Q2 2026, a 12% increase from Q1. Gunra's activity doubled from eight attacks in Q1 to at least four documented in Q2.

Key Findings

Commercialization accelerates attack velocity. The shift to a RaaS model has changed Gunra's operational profile. Instead of limiting attacks to the core group's capacity, the platform now allows multiple affiliates to conduct simultaneous campaigns. Your threat model must account for distributed attack patterns rather than a single adversary's resource constraints.

Firewall vulnerabilities remain the primary entry vector. Both CVE-2024-55591 and CVE-2025-24472 grant privileged access, allowing actors to bypass perimeter defenses. Once inside, Gunra operators exfiltrate data before deploying encryption payloads. The advisory documents ransom demands exceeding $10 million with five-to-seven-day payment deadlines, indicating actors have high confidence in their access persistence and data valuation.

Cross-platform capability expands the attack surface. Gunra initially targeted Windows environments but developed a Linux variant to compromise industrial control systems and cloud infrastructure. Researchers identified a cryptographic weakness in the Linux version that allows file recovery using timestamps without paying ransom, but only if your team identifies the variant during forensic analysis before the threat actors update their tools.

State-nexus infrastructure sharing complicates attribution. Two weeks before the FBI advisory, researchers documented tool and infrastructure overlap between Gunra and North Korea's Lazarus Group in attacks on South Korean organizations. This sharing arrangement means your incident response team may encounter nation-state-grade capabilities deployed by financially motivated criminals, requiring different containment and notification protocols than traditional ransomware.

Direct executive targeting bypasses IT departments. The FBI observed Gunra actors emailing management staff directly to demand payment, circumventing security and IT teams who typically handle incident response. This tactic exploits governance gaps where executives lack protocols for verifying ransom communications, potentially leading to unauthorized payments or premature disclosure decisions.

What This Means for Your Team

If you're running SOC 2 Type II or ISO/IEC 27001 programs, the Gunra advisory exposes control gaps that auditors will scrutinize in your next assessment. Your vulnerability management controls (ISO/IEC 27001 Annex A.12.6.1, SOC 2 CC7.1) must show that you're monitoring CISA's Known Exploited Vulnerabilities catalog and patching within prescribed timelines. The Fortinet CVEs were added to that catalog before Gunra began widespread exploitation, meaning delayed patching constitutes a material control deficiency.

For NERC CIP compliance programs, the targeting of industrial organizations creates specific obligations under CIP-007-6 (Systems Security Management) and CIP-010-4 (Configuration Change Management and Vulnerability Assessments). You'll need documented evidence that you assessed these vulnerabilities against your Electronic Security Perimeters and applied patches or compensating controls within your Transient Cyber Asset and Removable Media policies.

Healthcare organizations face compounded risk. HIPAA Security Rule §164.308(a)(1)(ii)(A) requires regular risk assessments that account for evolving threats. If your last assessment predates the Gunra emergence and you haven't updated your risk register to reflect RaaS targeting of healthcare providers, you're operating with an outdated threat profile. That gap becomes material during breach investigations when regulators reconstruct your pre-incident security posture.

Action Items by Priority

Immediate (within 48 hours):

Verify patch status for CVE-2024-55591 and CVE-2025-24472 across all Fortinet devices. If you can't patch immediately, implement the compensating controls CISA published: restrict management interface access to trusted internal networks, enable multi-factor authentication for all administrative accounts, and deploy detection rules for the indicators of compromise listed in the advisory. Document these compensating controls in your risk register with target remediation dates.

Establish executive communication protocols for ransom scenarios. Brief your C-suite and board that threat actors now bypass IT departments to contact executives directly. Create a decision tree that routes all extortion communications through your Computer Security Incident Response Team and legal counsel before any response. This isn't just operational hygiene; it's essential for maintaining attorney-client privilege during breach investigations.

Near-term (within 30 days):

Review your Privileged Access Management implementation against the advisory's attack chain. Gunra exploits firewall vulnerabilities to gain privileged credentials, then moves laterally using those credentials. Your PAM controls must enforce Just-in-Time Access for administrative functions and log all privileged session activity. If you're using static credentials for firewall management, you've created the exact vulnerability Gunra exploits.

Update your incident response playbooks to address RaaS-specific scenarios. Traditional ransomware playbooks assume a single threat actor with consistent tactics. RaaS platforms deploy multiple affiliates with varying skill levels and toolsets. Your containment procedures must account for simultaneous multi-vector attacks, and your communication templates must address the possibility of state-nexus infrastructure without making definitive attribution claims that could complicate law enforcement cooperation.

Ongoing:

Integrate CISA's Known Exploited Vulnerabilities catalog into your vulnerability management workflow. Don't wait for your scanner vendor to update severity scores; CISA's catalog represents actively exploited vulnerabilities that threat actors are using right now. Your patch prioritization process should treat KEV-listed items as emergency changes regardless of CVSS scores.

Conduct tabletop exercises that simulate RaaS attacks with executive targeting components. Most tabletops focus on technical containment, but Gunra's direct executive contact tactic requires testing your governance and communication protocols. Walk through scenarios where your CFO receives a ransom demand before your CISO knows about the breach, and document decision authorities for each stage of the response.

NERC CIP compliance

Promotional banner for the Penetration Report Template Kit

You Might Also Like