CISA warns Gunra hit 51 organizations as Linux flaw may enable recovery

Gunra, a ransomware-as-a-service operation derived from leaked Conti code, has breached at least 51 organizations across the Americas, Europe, the Middle East, Africa and the Asia-Pacific, hitting hospitals, government agencies and financial institutions, with most documented ransom demands exceeding $10 million. A joint advisory from six U.S. and South Korean government agencies said the group mainly gained access by exploiting Fortinet FortiOS and FortiProxy authentication-bypass flaws CVE-2024-55591 and CVE-2025-24472, though investigators also documented cases involving default SSL-VPN credentials and stolen session cookies. The alert also highlighted a separate March 2026 finding from Breakglass Intelligence that Gunra's Linux encryptor contains a cryptographic weakness: files with the .GNRA extension may be recoverable without payment if timestamps are preserved, because the malware uses a weak random-number process to generate encryption material. The advisory urges organizations to patch internet-facing systems, rotate credentials, isolate backups, audit MFA (multi-factor authentication) integrity and avoid rebooting or altering encrypted Linux files before incident responders assess recovery options.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.
CISA warns Gunra hit 51 organizations as Linux flaw may enable recovery - CoinPost Terminal