Active Exploitation of FortiOS/FortiProxy Authentication-Bypass Vulnerabilities (CVE-2024-55591, CVE-2025-24472) by Gunra Ransomware Affiliates
August 20th, 2026
Critical

Our Cyber Threat Intelligence Unit is tracking active exploitation of two FortiOS/FortiProxy authentication-bypass vulnerabilities, CVE-2024-55591 and CVE-2025-24472, by affiliates of Gunra, a double-extortion ransomware-as-a-service (RaaS) operation also tracked as Golden Community. This activity is detailed in joint advisory AA26-222A, published on August 10, 2026, by the FBI, CISA, DC3, NSA, U.S. Secret Service, and South Korea's National Police Agency (KNPA). Gunra emerged in April 2025, is built on leaked Conti source code, and formalized a structured RaaS affiliate program in January 2026. Affiliates gain initial access primarily through two Fortinet CVEs that create a persistent forticloud-sync admin account and, per KNPA, through exposed credentials and weak SSH access controls on internet-facing VPN gateways. From there, affiliates escalate privileges, move laterally, exfiltrate data, and encrypt files with ChaCha20/RSA-4096, giving victims five to seven days to negotiate before publishing stolen data. Confirmed victims span the healthcare, financial services, manufacturing, transportation, government, utilities, academia, media, retail, and nonprofit sectors across the Americas, Europe, the Middle East, Africa, and Asia-Pacific. Organizations running affected FortiOS/FortiProxy versions should treat this as an active, ongoing threat.
Technical Details
Threat Type: Ransomware-as-a-service (double extortion), using authentication-bypass exploitation for initial access.
Severity: Critical
CVE-2024-55591 (9.8) Critical
CVE-2025-24472 (8.1) High
Affected Systems: FortiOS 7.0.0–7.0.16 and FortiProxy 7.0.0–7.0.19/7.2.0–7.2.12
Threat Actors: Gunra RaaS affiliates (also tracked as Golden Community).
Initial Access: CVE-2024-55591 (Node.js websocket module) and CVE-2025-24472 (crafted CSF proxy requests, requiring Security Fabric enabled and known device serial numbers) both grant super-admin privileges and create a persistent forticloud-sync account with a hard-coded password via scheduled tasks; KNPA also observed credential exposure and weak SSH access controls on VPN gateways.
Privilege Escalation / Persistence: Default credentials with no lockout on an SSL-VPN admin account, bypass of forced password changes on a dual-homed unused account, and external SSH tunneling tools for persistent access.
Credential Access: NTDS dumping via Impacket secretsdump.py against domain controllers (multiple victims); single-victim cases included SSL-VPN traffic interception for VDI credentials/session cookies, theft of a Hiware access-control server's encryption key, and modification of VDI authentication files to force a fixed OTP to succeed, bypassing MFA.
Lateral Movement: RDP into VDI, AD, and staff desktops; SMB via Impacket psexec.py/smbclient.py
Defense Evasion: Log and command-history deletion, activity limited to late-night/early-morning hours, IsDebuggerPresent anti-debugging, exclusion of system-critical paths from encryption.
Collection & Exfiltration: main.exe exfiltrates OneDrive/SharePoint data; staged with 7-Zip, WinRAR, or RClone; exfiltrated via Mega or FTP (FileZilla), with volumes up to tens of terabytes.
Encryption: ChaCha20 + RSA-4096, files appended .ENCRT (.CRYPT on one July 2025 sample; Linux variant uses .GNRA), ransom note R3ADM3.txt, shadow-copy and, in one case, backup/DR-site deletion.
Linux Decryption Weakness (per AA26-222A, Incident Response section): As of March 2026, researchers identified that the Linux/.GNRA encryptor's key generator uses a predictable pseudorandom number generator seeded with the system clock (srand(time(NULL))) at encryption time, allowing defenders to potentially reconstruct keys from file timestamps and recover files without paying, if timestamps are preserved.

Impact
• Data Security: Exfiltration of business-critical documents, databases, PII, and internal email prior to encryption; potential unrecoverable data loss if decryption fails.
• System Availability: Encryption and deletion of backups/shadow copies can render systems and disaster-recovery capability inoperable.
• Business Operations: Sustained downtime, particularly disruptive for healthcare and critical-infrastructure operators.
• Financial: Ransom demands often exceeding tens of millions of USD, recovery, downtime, and remediation costs.
• Reputational: Public disclosure of leaked data on Gunra's DLS, loss of customer/partner trust.
Detection Method
Alert on creation of the account forticloud-sync or other unrecognized super-admin/local accounts on FortiOS/FortiProxy devices.
Alert on modifications to VDI/SSL-VPN authentication configuration files or MFA processing logic.
Monitor for use of Impacket components (psexec.py, secretsdump.py, smbclient.py), Mimikatz, and Sliver.
Monitor for outbound connections to Mega, FileZilla FTP sessions, and use of RClone, 7-Zip, or WinRAR preceding large data transfers.
Monitor for AnyDesk, Google Remote Desktop, and MobaXterm sessions inconsistent with normal admin behavior.
Alert on WMIC shadow-copy deletion commands (vssadmin/WMIC.exe shadowcopy ... delete).
Review edge-device and VPN administrator logs for anomalous privileged actions, especially outside business hours (10:00 p.m.–6:00 a.m. local).
Indicators of Compromise
IP Addresses and Domains
Type | Indicator | Description |
IP Address | 23.239.119[.]2 | Gunra infrastructure (Jul 2025–Nov 2025) |
IP Address | 23.239.119[.]3 | Gunra infrastructure (Jul 2025–Nov 2025) |
IP Address | 23.239.119[.]4 | Gunra infrastructure (Jul 2025–Nov 2025) |
IP Address | 23.239.119[.]5 | Gunra infrastructure (Jul 2025–Nov 2025) |
IP Address | 23.239.119[.]6 | Gunra infrastructure (Jul 2025–Nov 2025) |
IP Address | 86.54.28[.]216 | Gunra infrastructure (Jun–Jul 2025) |
IP Address | 103.125.234[.]14 | Gunra infrastructure (Nov–Dec 2025) |
IP Address | 70.36.99[.]82 | Gunra infrastructure (Nov–Dec 2025) |
IP Address | 211.21.210[.]181 | Gunra infrastructure (Nov–Dec 2025) |
IP Address | 123.184.143[.]105 | Gunra infrastructure (Nov–Dec 2025) |
IP Address | 182.204.21[.]240 | Gunra infrastructure (Nov–Dec 2025) |
IP Address | 182.204.16[.]112 | Gunra infrastructure (Nov–Dec 2025) |
IP Address | 123.244.187[.]144 | Gunra infrastructure (Nov–Dec 2025) |
IP Address | 182.204.39[.]118 | Gunra infrastructure (Nov–Dec 2025) |
IP Address | 67.43.53[.]10 | Gunra infrastructure (Nov–Dec 2025) |
IP Address | 123.246.37[.]108 | Gunra infrastructure (Nov–Dec 2025) |
IP Address | 91.201.66[.]146 | Gunra infrastructure (Nov–Dec 2025) |
Domain | datapub[.]news | Former clearnet mirror of Gunra's Tor DLS (Jun–Jul 2025) |
Domain | gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad[.]onion | Gunra Tor DLS (Apr 2025–Feb 2026) |
Domain | lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd[.]onion | Gunra Tor DLS (Mar–Jul 2026) |
Domain | nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd[.]onion | Gunra Tor DLS (Jan 2026) |
Email Addresses
Type | Indicator | Description |
Email Address | a00f105546345756@proton[.]me | Ransom negotiation |
Email Address | 4569f6322bc3b22e9@proton[.]me | Ransom negotiation |
Email Address | ilovemycubscout@gmail[.]com | Ransom negotiation |
Email Address | 6449a3c1e612168526@proton[.]me | Ransom negotiation |
qTox IDs
Type | Indicator | Description |
qTox ID | 2507312EC10BB44ED9DAA04E3C5C27E8C13154649B1A02E73ACFAE1681EE0208D05133A8FB22 | Ransom negotiation |
qTox ID | 0FE87CED0C611AE97E049C64288557F49E8271E91399E849328B078DA789A573031783235BEF | Ransom negotiation |
qTox ID | 47829AF1C943D4C296C910706923AS199BDA4995B076ED9A9016F7DEF161D445DF00F13E6900 | Ransom negotiation |
qTox ID | 9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47 | Ransom negotiation |
File Hashes
Type | Indicator | Description |
SHA-256 | 2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751 | main.exe — OneDrive/SharePoint exfiltration tool |
SHA-256 | 834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1 | main.exe — OneDrive/SharePoint exfiltration tool |
SHA-256 | 91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0 | cryptor.exe — malicious executable |
SHA-256 | a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9 | msmp.exe — malicious executable |

Recommendations
Patch FortiOS and FortiProxy to versions unaffected by CVE-2024-55591 and CVE-2025-24472 immediately; verify patch status across all internet-facing devices.
Audit FortiOS/FortiProxy devices and domain controllers for unrecognized accounts, particularly forticloud-sync.
Require MFA on all VPN, webmail, and critical-system access, and audit authentication configuration files for unauthorized modification.
Enforce account lockout on SSL-VPN admin accounts and eliminate default credentials.
Segment networks to limit lateral movement from a compromised device.
Maintain offline, immutable, tested backups in a physically separate location.
Load AA26-222A indicators into SIEM/detection tooling and map coverage against the advisory's MITRE ATT&CK techniques.
If hit by the Linux/.GNRA variant, do not reboot or wipe affected systems and consult incident response before paying. Preserving file timestamps is required to attempt free key recovery.
Conclusion
Gunra ransomware affiliates are actively exploiting CVE-2024-55591 and CVE-2025-24472 on internet-facing Fortinet devices to gain initial access, escalate privileges, exfiltrate data, and deploy ChaCha20/RSA-4096 encryption under a double-extortion model. Organizations running affected FortiOS/FortiProxy versions should patch immediately, audit the forticloud-sync account, enforce MFA and account lockout, and maintain tested offline backups. AA26-222A remains at its original August 10, 2026 version; the advisory itself flags independent March 2026 research from Breakglass Intelligence indicating that Linux/.GNRA-encrypted files may be recoverable without paying the ransom, provided file timestamps are preserved.
References
https://media.defense.gov/2026/Aug/10/2003976697/-1/-1/0/CSA_STOPRANSOMWARE_GUNRA_RANSOMWARE.PDF
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
https://www.ic3.gov/CSA/2026/260810.pdf
https://fortiguard.fortinet.com/psirt/FG-IR-24-535
https://nvd.nist.gov/vuln/detail/CVE-2024-55591
https://nvd.nist.gov/vuln/detail/CVE-2025-24472
https://cybelangel.com/blog/gunra-ransomware-fbi-advisory-2026/