top of page

Active Exploitation of FortiOS/FortiProxy Authentication-Bypass Vulnerabilities (CVE-2024-55591, CVE-2025-24472) by Gunra Ransomware Affiliates

August 20th, 2026

Critical

Our Cyber Threat Intelligence Unit is tracking active exploitation of two FortiOS/FortiProxy authentication-bypass vulnerabilities, CVE-2024-55591 and CVE-2025-24472, by affiliates of Gunra, a double-extortion ransomware-as-a-service (RaaS) operation also tracked as Golden Community. This activity is detailed in joint advisory AA26-222A, published on August 10, 2026, by the FBI, CISA, DC3, NSA, U.S. Secret Service, and South Korea's National Police Agency (KNPA). Gunra emerged in April 2025, is built on leaked Conti source code, and formalized a structured RaaS affiliate program in January 2026. Affiliates gain initial access primarily through two Fortinet CVEs that create a persistent forticloud-sync admin account and, per KNPA, through exposed credentials and weak SSH access controls on internet-facing VPN gateways. From there, affiliates escalate privileges, move laterally, exfiltrate data, and encrypt files with ChaCha20/RSA-4096, giving victims five to seven days to negotiate before publishing stolen data. Confirmed victims span the healthcare, financial services, manufacturing, transportation, government, utilities, academia, media, retail, and nonprofit sectors across the Americas, Europe, the Middle East, Africa, and Asia-Pacific. Organizations running affected FortiOS/FortiProxy versions should treat this as an active, ongoing threat.

Technical Details

  • Threat Type: Ransomware-as-a-service (double extortion), using authentication-bypass exploitation for initial access.

  • Severity: Critical

    • CVE-2024-55591 (9.8) Critical

    • CVE-2025-24472 (8.1) High

  • Affected Systems: FortiOS 7.0.0–7.0.16 and FortiProxy 7.0.0–7.0.19/7.2.0–7.2.12

  • Threat Actors: Gunra RaaS affiliates (also tracked as Golden Community).

  • Initial Access: CVE-2024-55591 (Node.js websocket module) and CVE-2025-24472 (crafted CSF proxy requests, requiring Security Fabric enabled and known device serial numbers) both grant super-admin privileges and create a persistent forticloud-sync account with a hard-coded password via scheduled tasks; KNPA also observed credential exposure and weak SSH access controls on VPN gateways.

  • Privilege Escalation / Persistence: Default credentials with no lockout on an SSL-VPN admin account, bypass of forced password changes on a dual-homed unused account, and external SSH tunneling tools for persistent access.

  • Credential Access: NTDS dumping via Impacket secretsdump.py against domain controllers (multiple victims); single-victim cases included SSL-VPN traffic interception for VDI credentials/session cookies, theft of a Hiware access-control server's encryption key, and modification of VDI authentication files to force a fixed OTP to succeed, bypassing MFA.

  • Lateral Movement: RDP into VDI, AD, and staff desktops; SMB via Impacket psexec.py/smbclient.py

  • Defense Evasion: Log and command-history deletion, activity limited to late-night/early-morning hours, IsDebuggerPresent anti-debugging, exclusion of system-critical paths from encryption.

  • Collection & Exfiltration: main.exe exfiltrates OneDrive/SharePoint data; staged with 7-Zip, WinRAR, or RClone; exfiltrated via Mega or FTP (FileZilla), with volumes up to tens of terabytes.

  • Encryption: ChaCha20 + RSA-4096, files appended .ENCRT (.CRYPT on one July 2025 sample; Linux variant uses .GNRA), ransom note R3ADM3.txt, shadow-copy and, in one case, backup/DR-site deletion.

  • Linux Decryption Weakness (per AA26-222A, Incident Response section): As of March 2026, researchers identified that the Linux/.GNRA encryptor's key generator uses a predictable pseudorandom number generator seeded with the system clock (srand(time(NULL))) at encryption time, allowing defenders to potentially reconstruct keys from file timestamps and recover files without paying, if timestamps are preserved.

Image by ThisisEngineering

Impact

Data Security: Exfiltration of business-critical documents, databases, PII, and internal email prior to encryption; potential unrecoverable data loss if decryption fails.

System Availability: Encryption and deletion of backups/shadow copies can render systems and disaster-recovery capability inoperable.

Business Operations: Sustained downtime, particularly disruptive for healthcare and critical-infrastructure operators.

Financial: Ransom demands often exceeding tens of millions of USD, recovery, downtime, and remediation costs.

Reputational: Public disclosure of leaked data on Gunra's DLS, loss of customer/partner trust.

Detection Method

  • Alert on creation of the account forticloud-sync or other unrecognized super-admin/local accounts on FortiOS/FortiProxy devices.

  • Alert on modifications to VDI/SSL-VPN authentication configuration files or MFA processing logic.

  • Monitor for use of Impacket components (psexec.py, secretsdump.py, smbclient.py), Mimikatz, and Sliver.

  • Monitor for outbound connections to Mega, FileZilla FTP sessions, and use of RClone, 7-Zip, or WinRAR preceding large data transfers.

  • Monitor for AnyDesk, Google Remote Desktop, and MobaXterm sessions inconsistent with normal admin behavior.

  • Alert on WMIC shadow-copy deletion commands (vssadmin/WMIC.exe shadowcopy ... delete).

  • Review edge-device and VPN administrator logs for anomalous privileged actions, especially outside business hours (10:00 p.m.–6:00 a.m. local).

Indicators of Compromise

IP Addresses and Domains

Type

Indicator

Description

IP Address

23.239.119[.]2

Gunra infrastructure (Jul 2025–Nov 2025)

IP Address

23.239.119[.]3

Gunra infrastructure (Jul 2025–Nov 2025)

IP Address

23.239.119[.]4

Gunra infrastructure (Jul 2025–Nov 2025)

IP Address

23.239.119[.]5

Gunra infrastructure (Jul 2025–Nov 2025)

IP Address

23.239.119[.]6

Gunra infrastructure (Jul 2025–Nov 2025)

IP Address

86.54.28[.]216

Gunra infrastructure (Jun–Jul 2025)

IP Address

103.125.234[.]14

Gunra infrastructure (Nov–Dec 2025)

IP Address

70.36.99[.]82

Gunra infrastructure (Nov–Dec 2025)

IP Address

211.21.210[.]181

Gunra infrastructure (Nov–Dec 2025)

IP Address

123.184.143[.]105

Gunra infrastructure (Nov–Dec 2025)

IP Address

182.204.21[.]240

Gunra infrastructure (Nov–Dec 2025)

IP Address

182.204.16[.]112

Gunra infrastructure (Nov–Dec 2025)

IP Address

123.244.187[.]144

Gunra infrastructure (Nov–Dec 2025)

IP Address

182.204.39[.]118

Gunra infrastructure (Nov–Dec 2025)

IP Address

67.43.53[.]10

Gunra infrastructure (Nov–Dec 2025)

IP Address

123.246.37[.]108

Gunra infrastructure (Nov–Dec 2025)

IP Address

91.201.66[.]146

Gunra infrastructure (Nov–Dec 2025)

Domain

datapub[.]news

Former clearnet mirror of Gunra's Tor DLS (Jun–Jul 2025)

Domain

gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad[.]onion

Gunra Tor DLS (Apr 2025–Feb 2026)

Domain

lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd[.]onion

Gunra Tor DLS (Mar–Jul 2026)

Domain

nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd[.]onion

Gunra Tor DLS (Jan 2026)

Email Addresses

Type

Indicator

Description

Email Address

a00f105546345756@proton[.]me

Ransom negotiation

Email Address

4569f6322bc3b22e9@proton[.]me

Ransom negotiation

Email Address

ilovemycubscout@gmail[.]com

Ransom negotiation

Email Address

6449a3c1e612168526@proton[.]me

Ransom negotiation

qTox IDs

Type

Indicator

Description

qTox ID

2507312EC10BB44ED9DAA04E3C5C27E8C13154649B1A02E73ACFAE1681EE0208D05133A8FB22

Ransom negotiation

qTox ID

0FE87CED0C611AE97E049C64288557F49E8271E91399E849328B078DA789A573031783235BEF

Ransom negotiation

qTox ID

47829AF1C943D4C296C910706923AS199BDA4995B076ED9A9016F7DEF161D445DF00F13E6900

Ransom negotiation

qTox ID

9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47

Ransom negotiation

File Hashes

Type

Indicator

Description

SHA-256

2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751

main.exe — OneDrive/SharePoint exfiltration tool

SHA-256

834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1

main.exe — OneDrive/SharePoint exfiltration tool

SHA-256

91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0

cryptor.exe — malicious executable

SHA-256

a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9

msmp.exe — malicious executable


mix of red, purple, orange, blue bubble shape waves horizontal for cybersecurity and netwo

Recommendations

  • Patch FortiOS and FortiProxy to versions unaffected by CVE-2024-55591 and CVE-2025-24472 immediately; verify patch status across all internet-facing devices.

  • Audit FortiOS/FortiProxy devices and domain controllers for unrecognized accounts, particularly forticloud-sync.

  • Require MFA on all VPN, webmail, and critical-system access, and audit authentication configuration files for unauthorized modification.

  • Enforce account lockout on SSL-VPN admin accounts and eliminate default credentials.

  • Segment networks to limit lateral movement from a compromised device.

  • Maintain offline, immutable, tested backups in a physically separate location.

  • Load AA26-222A indicators into SIEM/detection tooling and map coverage against the advisory's MITRE ATT&CK techniques.

  • If hit by the Linux/.GNRA variant, do not reboot or wipe affected systems and consult incident response before paying. Preserving file timestamps is required to attempt free key recovery.

Conclusion

Gunra ransomware affiliates are actively exploiting CVE-2024-55591 and CVE-2025-24472 on internet-facing Fortinet devices to gain initial access, escalate privileges, exfiltrate data, and deploy ChaCha20/RSA-4096 encryption under a double-extortion model. Organizations running affected FortiOS/FortiProxy versions should patch immediately, audit the forticloud-sync account, enforce MFA and account lockout, and maintain tested offline backups. AA26-222A remains at its original August 10, 2026 version; the advisory itself flags independent March 2026 research from Breakglass Intelligence indicating that Linux/.GNRA-encrypted files may be recoverable without paying the ransom, provided file timestamps are preserved.

bottom of page