RansomwareAug 11, 2026
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
Gunra ransomware gang uses Fortinet flaws and leaked Conti code to target critical infrastructure.
Summary
The Gunra ransomware-as-a-service operation is actively exploiting older vulnerabilities in Fortinet firewall and VPN appliances to gain access to critical infrastructure targets. Leveraging leaked Conti ransomware code, the group has demonstrated an ability to bypass multi-factor authentication (MFA) mechanisms, increasing its success rate against organizations that have implemented such security measures.
Indicators of Compromise
- malware — Gunra
- malware — Conti
Entities
Fortinet firewall (product)Fortinet VPN appliance (product)Gunra (threat_actor)