Gunra Ransomware: 51 Victims After Exploiting 2 Fortinet & Schneider Flaws
A joint US-South Korea advisory reveals Gunra ransomware has hit 51 organizations by weaponizing CVE-2024-5559 in Schneider Electric gear and CVE-2025-24472 in Fortinet products. The group uses double extortion, phishing, and advanced encryption, having launched a formal RaaS program in January 2026.
Cybersecurity briefing
Key takeaways
- A joint US-South Korea advisory reveals Gunra ransomware has hit 51 organizations by weaponizing CVE-2024-5559 in Schneider Electric gear and CVE-2025-24472 in Fortinet products.
- The group uses double extortion, phishing, and advanced encryption, having launched a formal RaaS program in January 2026.
- Unknown
- The Hacker News
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1Gunra has listed 51 victims on its data leak site since emerging in April 2025, with targets concentrated in Australia, East Asia, and Europe.
- 2The group exploits two vulnerabilities: CVE-2024-5559 (Schneider Electric PowerLogic P5) and CVE-2025-24472 (Fortinet FortiOS/FortiProxy) to gain initial access.
- 3Gunra uses phishing as its main attack vector and employs advanced stream ciphers (Salsa20 or ChaCha20) to encrypt files up to 9 terabytes in size.
- 4A formal ransomware-as-a-service (RaaS) affiliate program was launched on dark web forums in January 2026, scaling the operation globally.
- 5Victims are given five to seven days to pay before stolen data is published; the group operates a double extortion model.
- 6Targeted sectors include healthcare, financial services, government, and critical infrastructure, prompting a joint advisory from U.S. and South Korean agencies.
Concentration in Australia, East Asia, and Europe; only 3 in US/Canada
Gunra
Company- Emerged
- April 2025
- Victims
- 51
- RaaS Launch
- January 2026
Ransomware gang derived from Conti, active since April 2025. Uses phishing and exploits Fortinet/Schneider Electric flaws for double extortion. Launched RaaS in Jan 2026.
Analysis
For security teams, the Gunra advisory is a stark reminder that even large vendors' known vulnerabilities can become the entry point for sophisticated ransomware operations. The exploitation of a medium-voltage gear flaw alongside a firewall/proxy vulnerability shows how attackers chain weaknesses across IT and OT environments. With 51 victims already identified, defenders need to assess exposure immediately.
Cybersecurity and intelligence agencies from the United States and South Korea have issued a joint advisory warning of active exploitation by the Gunra ransomware group, which is leveraging two critical security flaws to breach networks worldwide. The vulnerabilities – CVE-2024-5559 in Schneider Electric's PowerLogic P5 medium-voltage switchgear and CVE-2025-24472 in Fortinet's FortiOS and FortiProxy appliances – provide initial access, after which attackers deploy Gunra ransomware in double-extortion operations that combine data theft with file encryption. The group threatens to publish stolen data on its leak site unless payment is made within five to seven days.
Cybersecurity and Infrastructure Security Agency (CISA) has underscored the urgency, with Acting Executive Assistant Director Chris Butera calling Gunra “another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S.
Emerging in April 2025, Gunra has already claimed 51 victims across sectors including healthcare, financial services, government, and critical infrastructure. The majority of victims are located in Australia, East Asia, and Europe, with only three reported from Canada and the United States – a geographic pattern that suggests a deliberate targeting strategy or the use of regional affiliates. The group relies on phishing as its primary initial access vector, delivering malicious payloads before moving laterally and encrypting large files – reportedly up to 9 terabytes – using advanced stream ciphers such as Salsa20 or ChaCha20. This technical capability points to a well-funded and operationally mature threat actor, likely derived from the notorious Conti ransomware lineage, given the presence of Conti source code.
In January 2026, Gunra formalized its business model by launching a ransomware-as-a-service (RaaS) affiliate program on dark web forums, providing partners with a complete management panel, negotiation tools, and a support infrastructure. This shift to an affiliate model dramatically increases the group’s scalability and makes it harder to attribute attacks, as multiple independent actors may now operate under the Gunra banner using the same toolset. The combination of easily exploitable public-facing vulnerabilities and a plug-and-play RaaS kit creates a high-severity risk environment for organizations that have not yet patched their Fortinet and Schneider Electric devices.
The market implications extend beyond immediate disruption. Both Fortinet and Schneider Electric face potential reputational damage and, depending on contractual obligations and liability claims, direct financial exposure. For end-user organizations, particularly those in critical infrastructure and healthcare, the cost of an incident can run into millions of dollars from downtime, remediation, regulatory fines, and ransom payments. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has underscored the urgency, with Acting Executive Assistant Director Chris Butera calling Gunra “another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations.”
What to Watch
From a technical defense standpoint, the advisory highlights a familiar but still worrying pattern: threat actors continue to succeed by exploiting known, patchable vulnerabilities. CVE-2025-24472, which affects Fortinet’s widely deployed firewalls and proxies, and CVE-2024-5559, affecting specialized power management equipment, both require immediate attention. Organizations using these products should prioritize patching, implement network segmentation, enforce multi-factor authentication, and monitor for unusual outbound traffic that could indicate data exfiltration. The Gunra case also reinforces the importance of dark web monitoring, as the group’s leak site and RaaS program are actively used to pressure victims.
Looking forward, the convergence of RaaS expansion and vulnerability exploitation suggests that Gunra will continue to grow its victim count. The group’s relative avoidance of North American targets so far may change as it scales operations through affiliates. Intelligence sharing between U.S. and South Korean agencies is expected to intensify, potentially leading to technical countermeasures, disruption operations, or sanctions against the individuals behind Gunra. For security teams and investors alike, this story serves as a reminder that the enterprise attack surface is constantly expanding, and the cost of unpatched vulnerabilities continues to rise.
Timeline
Timeline
Gunra ransomware emerges
The Gunra ransomware group is first observed in the wild, targeting global organizations with double extortion tactics.
Formal RaaS affiliate program launched
Gunra operators announce a ransomware-as-a-service program on dark web forums, providing affiliates with a management panel and tools.
Joint US-South Korea advisory issued
CISA and South Korean intelligence agencies release a cybersecurity advisory detailing Gunra's exploitation of Fortinet and Schneider Electric flaws.
Source cluster
Primary reporting
Cite This Page
"Gunra Ransomware: 51 Victims After Exploiting 2 Fortinet & Schneider Flaws." Cyber Intelligence Brief, August 12, 2026. https://getcyberbrief.com/story/gunra-ransomware-exploits-fortinet-schneider-flaws-51-victims
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |