Healthcare Orgs Warned About Ransomware Attacks Exploiting Unpatched Fortinet Devices
Cybersecurity agencies in the United States and South Korea have issued a warning about Gunra, a ransomware-as-a-service (RaaS) operation that has started targeting government and critical infrastructure entities, including healthcare organizations.
The financially motivated threat group was first identified in 2025, and in 2026, the group started running a RaaS operation, recruiting experienced affiliates from other groups to conduct attacks for a percentage of any ransoms generated. The group is also actively recruiting initial access brokers (IABs) and is advertising for cybersecurity professionals such as ethical hackers and penetration testers who want to make more money from their offensive cybersecurity skills.
The group uses hacking tools utilized by North Korean government-linked hackers, although it is unclear if Gunra is a state-sponsored hacking group. The group engages in double extortion ransomware attacks, exfiltrating sensitive data and encrypting files. A ransom payment is required to prevent the publication/sale of stolen data via its dark web data leak site, and to obtain the keys to decrypt data.
Victims have come from several sectors including academia, financial services, manufacturing, construction, media, retail, transportation, government, and healthcare, and attacks span multiple continents. The #StopRansomware cybersecurity advisory is specifically aimed at government and critical infrastructure entities.
The group has been observed using known, exploited vulnerabilities for initial access, especially vulnerabilities in Internet-facing systems such as VPN gateways, remote desktop protocol-exposed infrastructure, and firewalls. Some attacks have exploited the FortiOS and FortiProxy authentication bypass vulnerabilities CVE-2025-24472 and CVE-2024-55591, patches for which are available. In both cases, the hackers exploited the vulnerabilities, created super-admin accounts, modified firewall configurations, and established SSL VPN tunnels for persistent remote access. The FBI has warned that Gunra actors have also exploited credential-exposure and Secure Shell (SSH) access control vulnerabilities in internet-facing VPN gateways.
After gaining access, Gunra actors use multiple stealth and defense impairment techniques to hinder detection and analysis, such as deleting system and access logs, wiping command history, and timing malicious activities and reconnaissance when victims are less likely to be monitoring systems closely. Sensitive data is identified and exfiltrated, files are encrypted, and ransom notes are dropped in all affected locations.
While not currently one of the most prolific ransomware groups, Gunra certainly has ambitions to become a major player, and attacks are likely to increase as it recruits more affiliates, IABs, and pentesters. The most important step to take to harden security is to monitor for known exploited vulnerabilities (KEVs) and prioritize patching KEVs in internet-facing systems, especially VPNs, RDP-exposed infrastructure, and firewalls.
The impact of attacks can be reduced by segmenting networks to restrict lateral movement and creating immutable backups, storing them in physically separate, segmented locations. Backups should be regularly tested to ensure data can be recovered.
