Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

The Gunra ransomware gang is exploiting old Fortinet firewall and VPN flaws to bypass multi-factor authentication and breach critical infrastructure, using leaked Conti ransomware code to increase its success.

The Gunra ransomware-as-a-service group is exploiting known Fortinet vulnerabilities to breach critical infrastructure organizations, bypassing multi-factor authentication. Using leaked source code from the Conti ransomware operation, the gang targets unpatched Fortinet firewalls and VPN appliances with old flaws. Once inside, they disable or evade MFA protections, enabling lateral movement and data encryption. The attacks highlight ongoing risks from unpatched edge devices and the reuse of Conti's code by new threat actors.