Gunra Ransomware Targets Fortinet VPNs to Bypass MFA and Encrypt Enterprise Networks

Gunra ransomware is actively exploiting vulnerabilities in Fortinet VPN and firewall appliances to gain enterprise access, bypass MFA, steal sensitive data, and deploy ransomware. Security agencies including the FBI and CISA have warned organizations about attacks involving CVE-2024-55591 and CVE-2025-24472.

Gunra Ransomware Targets Fortinet VPNs to Bypass MFA and Encrypt Enterprise NetworksGunra Ransomware Targets Fortinet VPNs to Bypass MFA and Encrypt Enterprise Networks

After gaining access, Gunra affiliates use credential-dumping and lateral-movement tools to compromise additional systems and extract sensitive information from Microsoft OneDrive, SharePoint, and internal networks. Stolen data can reach several terabytes before attackers encrypt systems using ChaCha20 and RSA-4096, followed by ransom demands and threats to publish the stolen information.

Organizations should immediately patch exposed Fortinet VPN infrastructure, review authentication configurations, monitor for unauthorized changes, segment critical networks, and maintain offline or immutable backups. Security teams should also monitor for suspicious VPN activity, credential theft, lateral movement, and known Gunra indicators of compromise.


Defend your enterprise against ransomware, VPN attacks, MFA bypass, and data theft with NPAV EDR, Business Security, and Data Loss Prevention.