Back to Feed
RansomwareAug 11, 2026

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

Gunra ransomware gang uses Fortinet flaws and leaked Conti code to target critical infrastructure.

Summary

The Gunra ransomware-as-a-service operation is actively exploiting older vulnerabilities in Fortinet firewall and VPN appliances to gain access to critical infrastructure targets. Leveraging leaked Conti ransomware code, the group has demonstrated an ability to bypass multi-factor authentication (MFA) mechanisms, increasing its success rate against organizations that have implemented such security measures.

Indicators of Compromise

  • malware — Gunra
  • malware — Conti

Entities

Fortinet firewall (product)Fortinet VPN appliance (product)Gunra (threat_actor)