Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [incident, ransomware, ransomware-group, fortinet, schneider-electric, ot, initial-access] ยท confidence: high ยท affected_sectors: [technology, government, finance, healthcare, energy] ยท au_impact: true

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

New reporting extends the joint FBI/CISA advisory with exploitation detail: Gunra, the Conti-derived ransomware-as-a-service, gains initial access via CVE-2024-5559 (Schneider Electric PowerLogic P5) and CVE-2025-24472 (Fortinet FortiOS/FortiProxy), then deploys a double-extortion locker.

Summary

Gunra, a Conti-derived RaaS operation, is gaining initial access via CVE-2024-5559 (Schneider Electric PowerLogic P5) and CVE-2025-24472 (Fortinet FortiOS/FortiProxy), then deploying its double-extortion locker with data published on a leak site within five to seven days of non-payment.

Victim scope: Ransomware.Live counts 51 listed victims since April 2025, most in South Korea, Brazil, Spain, Thailand and Hong Kong โ€” with most victims located in Australia, East Asia and Europe and only three in Canada and the US. Its named targets (healthcare, financial services, government, professional services) map onto ASIC/APRA-regulated sectors.

Evolution: The FBI reports Gunra is adopting new branding aliases such as Golden Community and recruiting penetration testers and "ethical hackers" as initial-access brokers. Its Linux builds carry a known "catastrophic cryptographic weakness" that lets victims recover the encryption key.

Date

  • Reported: 2026-08-11 (day after joint FBI/CISA advisory)

Source

Related Pages