Gunra Ransomware Targets Critical Infrastructure Through Fortinet And Schneider Electric Flaws

Published:

Cybersecurity and intelligence agencies from South Korea and the United States have issued a joint warning about Gunra ransomware attacks targeting critical infrastructure organizations across multiple countries. According to the advisory, the ransomware group has been exploiting known security vulnerabilities in internet facing Schneider Electric PowerLogic P5 and Fortinet FortiOS and FortiProxy appliances to gain initial access before deploying ransomware. The attacks have affected organizations operating in healthcare and public health, financial services, government services and facilities, as well as professional and nonprofit sectors. Officials described Gunra as another ransomware variant contributing to the growing trend of disruptive attacks against organizations worldwide. The ransomware operation follows a double extortion model in which attackers first steal sensitive information before encrypting systems, increasing pressure on victims to pay ransom demands within five to seven days or risk having their stolen data published on dedicated leak sites. Data published by Ransomware.Live shows Gunra has listed 51 victims since emerging in April 2025, with organizations in South Korea, Brazil, Spain, Thailand, and Hong Kong accounting for most of the reported incidents.

According to the advisory, Gunra operators have exploited vulnerabilities tracked as CVE 2024 5559 in Schneider Electric PowerLogic P5 systems and CVE 2025 24472 affecting Fortinet FortiOS and FortiProxy appliances. Researchers noted that phishing campaigns also remain an important infection vector used to deliver malicious payloads before negotiations are conducted through a WhatsApp themed communication panel. Security researchers have previously reported that the ransomware is capable of encrypting files as large as 9TB within a relatively short period by using advanced stream cipher encryption algorithms such as Salsa20 and ChaCha20. The operation has also expanded its activities by launching a formal Ransomware as a Service affiliate program that provides affiliates with ransomware builders, management panels, documentation, and payloads supporting both Windows and Linux environments. Although the Linux version contains a cryptographic weakness identified earlier this year that allows recovery of encrypted files without paying the ransom in some cases, the ransomware continues to pose a significant threat because of its advanced operational capabilities and aggressive extortion tactics. The FBI has also observed the threat group adopting alternative branding such as Golden Community while recruiting penetration testers and ethical hackers to function as initial access brokers in exchange for a share of ransom payments.

Investigators have documented sophisticated attack techniques used after initial compromise. Gunra operators rely on Impacket tools including psexec.py and smbclient.py to move laterally across compromised networks using the Server Message Block protocol, while secretsdump.py is used to extract password hashes from Active Directory domain controllers. The attackers attempt to remove evidence of their activities by deleting access logs and command histories while conducting reconnaissance primarily during overnight hours. Data theft operations frequently target Microsoft OneDrive and SharePoint through a malicious executable named main.exe. In some incidents, attackers compressed terabytes of sensitive corporate information before transferring it to the MEGA file sharing platform. Authorities also observed the compromise of virtual desktop infrastructure environments used by IT administrators, allowing attackers to obtain confidential system configuration files and enterprise credentials. In one South Korean investigation, attackers manipulated SSL VPN traffic control functions to intercept authentication credentials and session cookies before hijacking legitimate user sessions. They also modified authentication processing files on virtual desktop infrastructure portals to bypass multi factor authentication by accepting attacker designated one time password values. Additional activities included exploiting default SSL VPN credentials, installing OpenSSH for persistent access, modifying dormant administrative accounts, stealing encryption keys from Hiware system access control servers to decrypt enterprise passwords, and deleting backup data stored at both primary and disaster recovery facilities before ransomware deployment.

The latest advisory also highlights possible overlaps between Gunra operations and campaigns attributed to North Korean threat actors. Authorities noted that some attacks exploiting financial security software vulnerabilities have resulted in both malware deployment associated with state sponsored activity and Gunra ransomware infections, suggesting possible sharing of techniques, infrastructure, or limited operational collaboration. Researchers also pointed to watering hole campaigns exploiting a zero day vulnerability in AnySign4PC to distribute malware families including Struggle and Brandoor, which have previously been linked to Lazarus Group. Similar cooperation between ransomware operators and North Korean threat actors has been observed in earlier investigations involving Play, Qilin, and Medusa ransomware campaigns. Although the precise relationship remains unclear, cybersecurity agencies emphasize that organizations should focus on strengthening defensive measures by applying security updates to operating systems, software, and firmware, prioritizing remediation of known exploited vulnerabilities on internet facing systems, implementing network segmentation, enforcing strong authentication controls, and maintaining immutable backups stored separately from production environments. These measures, according to the advisory, can significantly reduce the risk of successful ransomware attacks and improve an organization’s ability to recover if an incident occurs.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img