On 11 August, CISA, the FBI, the NSA, the US Secret Service and their South Korean counterparts published a joint advisory on Gunra ransomware under the #StopRansomware banner. Gunra appeared in April 2025, derived from the Conti source code leaked in 2022, and in January 2026 it launched a formal affiliate programme: management panels, configurable payload builders, cross-platform variants. In other words, an attack capability once tied to a single crew is now rented out.
Known victims cluster in Australia, East Asia and Europe, led by South Korea, Brazil, Spain, Thailand and Hong Kong, with a handful of cases in Canada and the United States. The sectors targeted are the ones that cannot stop: healthcare, financial services, government bodies, professional services and nonprofits.
But the detail that should hold a risk owner's attention is neither the crew's name nor the geography. It is how ordinary the entry point is.
No zero-day, only patches that were already available
For initial access, Gunra affiliates exploit known flaws in internet-facing appliances: two Fortinet authentication bypasses (CVE-2024-55591 in FortiOS, CVE-2025-24472 in FortiProxy) and a flaw in Schneider Electric PowerLogic P5 (CVE-2024-5559). All of them have been documented and fixed for months, and the Fortinet flaws sit in CISA's catalogue of actively exploited vulnerabilities. Phishing rounds out the picture, but it is the perimeter that offers the most direct road in.
There is an irony worth naming: the compromised device is often a security device. A firewall, a VPN gateway, an access proxy. Which is to say, precisely the asset that appears in no monthly patch cycle, because the network team owns it, it does not reboot without a maintenance window, and nobody wants to touch it on a Friday.
The patch does not evict the attacker
The tradecraft described in the advisory carries a lesson many patch programmes miss. Once inside, the attackers modified the authentication processing files on the corporate virtual desktop access portal so that specific one-time password values would be accepted. Multifactor authentication stayed in place, visible on the dashboards, and protected nothing.
What follows is classic and effective: Impacket libraries for lateral movement and credential dumping, data exfiltration to a consumer file-sharing service, then Salsa20 or ChaCha20 stream encryption, fast enough to process several terabytes in a single overnight window. Victims who refuse to pay see their data published within five to seven days.
The governance lesson is direct: applying the patch closes the door, but it puts nobody out. After an edge appliance has been exposed for a long stretch, full remediation means rotating credentials and secrets, invalidating sessions, reviewing administrative accounts, and checking the configuration files of the authentication portal itself. A programme that measures "patch applied" without measuring "access revoked" can declare itself healthy while remaining occupied.
What your programme should take away
- Inventory what is reachable from the internet, continuously. You cannot patch what you do not know is exposed. Your external attack surface includes the forgotten appliance at a remote site, in an acquired subsidiary, or left over from a closed project.
- Give edge appliances the shortest patch deadline you have. They are pre-authentication, exposed to everyone, and exploited within days. They deserve an emergency lane separate from the monthly cycle, as we set out in our piece on vulnerability governance.
- Treat multifactor authentication as a control to verify, not a box to tick. If the server enforcing it is compromised, it no longer protects you. Monitor the integrity of the authentication components themselves.
- Segment so that the entrance is not the whole house. Access gained on a gateway should not open the path to backups and domain controllers.
- Make sure backups outlive the attacker. Immutable, offline, tested through real restores. That is what turns the decision not to pay into a logical conclusion rather than a gamble, as our article on a business continuity plan that survives a cyberattack explains.
The question for the board
Gunra becoming a service rented to affiliates changes the question worth asking. It is no longer whether your organisation interests one particular criminal group, but whether it presents an opening that an automated scan can spot. So the question fits in one sentence: "how many appliances do we expose to the internet, which of them carries our oldest unapplied patch, and who owns that number". An organisation that cannot answer within a day does not have a technical problem, it has a governance blind spot.
Where FortaRisks fits
The External attack surface module continuously discovers what your organisation actually exposes to the internet, including the assets nobody declares, and the Threat intelligence module cross-references those exposures with exploitation observed in the wild, so the patch queue follows real risk. To place your exposure in a few minutes, our free cyber risk score gives you a quantified starting point you can put in front of an executive committee.