Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
AI Summary
Gunra ransomware, a Conti-derived operation, has been actively targeting critical infrastructure sectors globally, including healthcare, financial services, and government facilities. The group exploits known vulnerabilities in Fortinet (CVE-2025-24472) and Schneider Electric (CVE-2024-5559) devices to gain initial access, then uses Impacket tools for lateral movement and credential dumping. Gunra employs a double extortion model, exfiltrating data before encryption, and has listed 51 victims on its leak site since April 2025, primarily in South Korea, Brazil, and Europe. The group has ties to affiliate programs, uses WhatsApp for negotiations, and has demonstrated advanced capabilities such as MFA bypass and session hijacking via SSL-VPN manipulation.
AI-extracted · verify before operational use