A Joint US-South Korea Advisory Names a New Extortion Gang
On August 10, 2026, CISA published advisory AA26-222A under its #StopRansomware series, co-authored with the FBI, the NSA, the U.S. Secret Service, the Department of Defense Cyber Crime Center and South Korea's National Police Agency. The advisory formally names Gunra as an active ransomware-as-a-service operation and traces its code lineage to the leaked source of the Conti ransomware family, a common ancestor for several extortion groups that have emerged since Conti's own operators dissolved the brand.
The authoring agencies describe Gunra affiliates as combining credential compromise, data theft and rapid encryption in double-extortion campaigns against healthcare systems, financial services firms, government agencies, professional services companies and nonprofits, with entry gained primarily through exposed VPN gateways, firewall appliances and RDP-accessible systems rather than through any novel exploit technique.
The Doors Gunra Walks Through Were Patched 18 Months Ago
The advisory identifies two specific vulnerabilities as Gunra's primary path into victim networks: CVE-2024-55591, an authentication-bypass flaw in Fortinet FortiOS, and CVE-2025-24472, the equivalent flaw in FortiProxy. Fortinet shipped fixes for these in January and February 2025 respectively, after both were disclosed as under active exploitation by other threat actors at the time.
That timeline matters more than the malware itself. Gunra did not need a fresh zero-day to breach 51 organisations since April 2025; it needed internet-facing Fortinet appliances that had gone eighteen months or more without the available patch. Given how widely FortiOS and FortiProxy are deployed across mid-size and large European organisations as VPN and perimeter infrastructure, an unpatched instance is not a rare finding in an external scan - it is a routine one.
9 Terabytes, 100 Threads: Inside the Encryption Playbook
Once inside, Gunra affiliates follow a now-familiar double-extortion sequence: steal data, encrypt systems, then demand payment for both a decryption key and a promise not to publish what was taken. The group's Linux variant is built for speed, supporting up to 100 parallel encryption threads and partial-file encryption using stream ciphers such as Salsa20 or ChaCha20, letting it encrypt datasets as large as 9 terabytes within a limited window rather than over days.
Victims who do not pay within five to seven days have their stolen data published on Gunra's leak site, with negotiations conducted through a Tor-based portal. The advisory's recommended defences are unglamorous by design: patch internet-facing VPN and firewall appliances, maintain offline and immutable backups, and segment networks so that a single compromised device cannot reach the rest of the environment.
Why Patch Lag, Not the Malware, Is the NIS2 Finding Here
For an EU organisation working through NIS2 Article 21's risk-management measures, or a UK operator under equivalent NCSC guidance, the actionable conclusion from this advisory is not about Gunra specifically. It is that an authentication-bypass flaw in widely deployed perimeter infrastructure, patched over a year ago and still described in an August 2026 federal advisory as an active breach vector, represents a vulnerability-management failure that predates and outlives any single ransomware brand.
The practical response is to treat this advisory as a trigger for an immediate FortiOS and FortiProxy version audit across every internet-facing appliance the organisation controls, not just the ones already flagged in existing patch-management dashboards, since it is precisely the forgotten or unmanaged appliance that a patch-lag flaw like this one is built to find.
Read next: DeadLock Hides Its Leak Site Inside a Blockchain | Clearing the Attacker Also Clears Your Logic



