< Back to all clusters
[TECHNOLOGY] · 6 sources

started · updated

Gunra ransomware exploits Fortinet flaws to bypass MFA

The ransomware landscape in 2026 is characterized by a shift toward vulnerability-driven intrusions and sophisticated extortion models. A primary threat is the Gunra ransomware group, a Conti-derived operation that has transitioned into a ransomware-as-a-service model known as ‘Golden Community.’

Gunra operators are specifically targeting Fortinet infrastructure, exploiting vulnerabilities in FortiOS and FortiProxy to bypass Multi-Factor Authentication (MFA). Techniques include session hijacking and tampering with authentication files to ensure one-time passwords always succeed. Once access is gained, the group uses tools like Impacket for lateral movement and exfiltrates data via a custom tool named ‘main.exe’ before encrypting files with ChaCha20/RSA-4096.

In the Americas, which accounted for 57% of global ransomware incidents in the first half of 2026, attackers are increasingly weaponizing edge infrastructure from providers such as Ivanti, Cisco, and Palo Alto Networks. The trend shows a strategic pivot from simple system encryption to high-leverage data exfiltration to maximize pressure on victims.

Entities

CISA · DeadLock Ransomware · FBI · Fortinet · Gunra Ransomware · Lazarus Group · Microsoft Threat Intelligence · Polygon