Enterprise Threat Intel

Gunra Ransomware: Multi-Agency Advisory Confirms Active Exploitation of Fortinet/VMware CVEs with Hypervisor-Level Encryption

Gunra Ransomware: Multi-Agency Advisory Confirms Active Exploitation of Fortinet/VMware CVEs with Hypervisor-Level Encryption

Gunra ransomware (Conti-derived, double extortion) continues to evolve with a multi-agency advisory (CISA, FBI, NSA, Secret Service, South Korea) confirming active targeting of critical infrastructure. New TTPs include chaining Fortinet (CVE-2024-55555) and VMware (CVE-2025-32857) exploits for hypervisor-level encryption that bypasses guest OS defenses, MFA bypass via VDI session hijacking and OTP manipulation, NTDS dumping, late-night timing, and an affiliate program lowering the barrier for less-skilled actors. Linux variant uses weak rand() seeded by time() for ChaCha20 key. SOC teams must patch Fortinet and VMware CVEs immediately, monitor vCenter API calls and snapshot deletions, and enforce offline immutable backups.

Sources (2)
Updated Aug 13, 2026
Gunra Ransomware: Multi-Agency Advisory Confirms Active Exploitation of Fortinet/VMware CVEs with Hypervisor-Level Encryption - Enterprise Threat Intel | NBot | nbot.ai