Gunra Ransomware Exploits Unpatched Fortinet & Schneider Electric Devices
Gunra ransomware is actively exploiting known vulnerabilities in Fortinet and Schneider Electric appliances to gain initial access to critical infrastructure networks worldwide. The group's double extortion model — combining data theft with encryption — dramatically increases the cost of inaction, as victims risk both operational disruption and public data exposure. The use of initial access brokers further accelerates the attack lifecycle, meaning unpatched internet-facing devices can be compromised and sold before defenders even detect the intrusion. This campaign underscores that unpatched edge devices remain one of the most reliably exploited entry points for ransomware operators targeting critical infrastructure.
Tactical Insight
Immediate Actions
- Apply all available patches for affected Fortinet and Schneider Electric appliances immediately, or isolate them from internet exposure until patched.
- Audit all internet-facing devices and disable any unnecessary services or management interfaces exposed externally.
Long-Term Improvements
- Establish a formal emergency patching SLA (e.g., ≤48 hours) for critical vulnerabilities on perimeter and OT/ICS devices.
- Implement strict network segmentation between IT and OT/critical infrastructure environments to limit lateral movement.
- Maintain a continuously updated asset inventory covering all network appliances, including firmware versions and patch status.
Detection Measures
- Deploy anomaly-based monitoring on edge devices to detect unusual authentication attempts or lateral movement indicative of initial access broker activity.
- Enable centralized logging for all perimeter appliances and set alerts for exploit signatures associated with known Fortinet and Schneider Electric CVEs.
- Integrate threat intelligence feeds to receive timely notification when vendor-specific vulnerabilities are being actively exploited in the wild.