Gunra, a ransomware-as-a-service operation, actively exploits vulnerabilities in Fortinet FortiGate firewalls and VPN appliances to compromise critical infrastructure networks. The group leverages both newly disclosed flaws and patched vulnerabilities in Fortinet equipment, combined with leaked Conti ransomware code, to establish initial network access.

The threat actor successfully bypasses multi-factor authentication during intrusions, a critical finding given the widespread adoption of MFA as a primary defensive control. Gunra targets critical infrastructure sectors where network disruption carries severe operational and safety consequences. The group's access to Conti source code, leaked following the original operation's law enforcement takedown, provides sophisticated ransomware capabilities that competing threat actors now utilize across the threat landscape.

Fortinet vulnerabilities exploited by Gunra include both patched flaws and zero-days. Legacy versions of FortiGate appliances remain in production across many organizations, creating extended exposure windows even after patches release. The combination of FortiGate access and VPN compromises grants Gunra direct pathways to internal networks without requiring employee credential theft or phishing campaigns.

Organizations operating Fortinet infrastructure must immediately verify current firmware versions across all FortiGate firewalls and VPN appliances. Assets running versions prior to recent security updates face active exploitation risk. Network defenders should assume that MFA alone will not stop determined attackers with direct firewall access, as Gunra demonstrates. Additional segmentation controls, detection of unusual admin account activity, and monitoring for lateral movement become essential when FortiGate compromise occurs.

The ransomware-as-a-service model enables relatively less-sophisticated operators to conduct enterprise-scale attacks by licensing code and infrastructure from experienced developers. Gunra's success against critical infrastructure indicates that this operational model, combined with access to leaked Conti capabilities,