Gunra ransomware operators are targeting critical infrastructure organizations by exploiting vulnerabilities in Fortinet firewalls and VPN appliances, according to multiple reports. The activity is linked to attempts to gain initial access and then exfiltrate large amounts of data.
The outlets describe the campaign as using stealthy tactics that focus on data theft. One report says the operators exfiltrate vast volumes of data from Microsoft services. Another adds that the group can bypass multi-factor authentication (MFA), which helps it maintain access once inside.
The reporting also frames the threat as part of a ransomware-as-a-service operation and notes that the group leverages previously leaked Conti ransomware code. Both accounts point to older, previously known weaknesses in perimeter security devices and emphasize that US and Korean authorities have issued warnings about the campaign’s methods and impact.