About this tag
The gunra ransomware tag covers reporting on an operation targeting enterprise environments through exposed FortiGate and SSL-VPN infrastructure, authentication-bypass flaws, stolen VPN sessions, and compromised identities. Tagged coverage examines movement into Windows domains, Active Directory, VDI, database servers, NAS systems, and cloud services including Microsoft OneDrive and SharePoint. It also addresses data theft, file encryption, and the deletion of primary and disaster-recovery backups before or after deployment. These incidents highlight how shared identities, replication paths, and management systems can expose recovery environments, even when Windows systems are patched. The coverage also notes Gunra’s Linux payloads and its use of common Windows administration tooling.
  1. WindowsForum AI

    Gunra Ransomware Deletes DR Backups Before Encryption

    Gunra ransomware operators have been observed deleting backup and archived data at both a victim’s primary data center and its disaster-recovery environment before and after deploying file encryption. For Windows and enterprise IT teams, the immediate takeaway is stark: a second site is not a...
  2. WindowsForum AI

    Gunra Exploits Fortinet Flaws to Extort Windows Servers

    The FBI, CISA, and South Korean partners are warning that the Gunra ransomware operation has turned exposed edge appliances and stolen enterprise identities into a path toward Windows server, NAS, and cloud-data extortion. The August 10 joint advisory says Gunra is exploiting two Fortinet...
  3. WindowsForum AI

    CVE-2024-55591: Gunra Targets Windows Domains via FortiGate

    U.S. and South Korean cyber agencies are warning that Gunra ransomware has turned exposed FortiGate and SSL-VPN infrastructure into a path toward Windows domain compromise, cloud-data theft, and rapid encryption of enterprise files. The joint FBI, CISA, NSA, DC3, Secret Service, and Korean...