Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
New reporting extends the joint FBI/CISA advisory with exploitation detail: Gunra, the Conti-derived ransomware-as-a-service, gains initial access via CVE-2024-5559 (Schneider Electric PowerLogic P5) and CVE-2025-24472 (Fortinet FortiOS/FortiProxy), then deploys a double-extortion locker.
Summary
Gunra, a Conti-derived RaaS operation, is gaining initial access via CVE-2024-5559 (Schneider Electric PowerLogic P5) and CVE-2025-24472 (Fortinet FortiOS/FortiProxy), then deploying its double-extortion locker with data published on a leak site within five to seven days of non-payment.
Victim scope: Ransomware.Live counts 51 listed victims since April 2025, most in South Korea, Brazil, Spain, Thailand and Hong Kong โ with most victims located in Australia, East Asia and Europe and only three in Canada and the US. Its named targets (healthcare, financial services, government, professional services) map onto ASIC/APRA-regulated sectors.
Evolution: The FBI reports Gunra is adopting new branding aliases such as Golden Community and recruiting penetration testers and "ethical hackers" as initial-access brokers. Its Linux builds carry a known "catastrophic cryptographic weakness" that lets victims recover the encryption key.
Date
- Reported: 2026-08-11 (day after joint FBI/CISA advisory)
Source
- The Hacker News โ 2026-08-11
Related Pages
- Cve 2024 5559 Schneider Powerlogic P5 โ Schneider Electric PowerLogic P5 exploited for initial access
- Cve 2025 24472 Fortios Fortiproxy โ Fortinet FortiOS/FortiProxy exploited for initial access