Gunra Ransomware Exploiting CVE-2024-5559 and CVE-2025-24472
Release Date: 10th August 2026
Impact : HIGH
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.
What is it?
On 10 August 2026, CISA, the FBI, the Department of Defense Cyber Crime Center, the National Security Agency, the U.S. Secret Service, and South Korea's National Police Agency issued a joint #StopRansomware advisory (AA26-222A) on Gunra, a ransomware-as-a-service operation derived from leaked Conti source code that first emerged in April 2025 and has listed at least 51 victims worldwide.
Gunra affiliates have been gaining initial access by exploiting two previously disclosed vulnerabilities: CVE-2024-5559, a risky cryptographic algorithm flaw (CVSS 6.1) in Schneider Electric PowerLogic P5 protective relays, and CVE-2025-24472, an authentication bypass vulnerability (CVSS 8.1) in Fortinet FortiOS and FortiProxy. Both already have patches available, but unpatched devices remain a live route into victim networks.
What are the systems affected?
Affected systems are internet-facing or physically accessible edge devices running unpatched versions of the two exploited products below, most consequential where they sit at the perimeter of healthcare, financial services, government, or critical manufacturing networks.
Schneider Electric PowerLogic P5 protective relays, firmware v01.500.104 and prior – (Affected, CVE-2024-5559)
Fortinet FortiOS 7.0.0 through 7.0.16 – (Affected, CVE-2025-24472)
Fortinet FortiProxy 7.0.0 through 7.0.19 – (Affected, CVE-2025-24472)
Fortinet FortiProxy 7.2.0 through 7.2.12 – (Affected, CVE-2025-24472)
Organisations in healthcare, financial services, government, and critical manufacturing are targeted sectors, alongside professional and nonprofit services.
What does this mean?
Gunra combines exploitation of these edge-device flaws with credential theft, living-off-the-land tooling, and a double-extortion payoff - deleting backups before encrypting production systems to remove the option of recovering without paying.
Step 1 - Initial Access
The actor exploits CVE-2025-24472 remotely against an internet-facing FortiOS/FortiProxy device to obtain super-admin privileges, or CVE-2024-5559 via access to a Schneider Electric PowerLogic P5 relay's front panel, then creates rogue admin or local accounts and adds them to SSL VPN user groups.
Step 2 - Credential Theft and Lateral Movement
Using Impacket tools (psexec.py, smbclient.py) over SMB, the actor moves laterally, then runs secretsdump.py against domain controllers to extract password hashes from the NTDS file, and in some cases accesses a system access control server to steal a symmetric key that decrypts stored enterprise server credentials.
Step 3 - Reconnaissance and Evasion
The actor operates mainly between 10 p.m. and 6 a.m., deletes access logs and clears command history, and harvests configuration data from the virtual desktop infrastructure (VDI) environments of IT personnel.
Step 4 - Double Extortion
Data is exfiltrated from OneDrive/SharePoint or compressed and sent to MEGA, and backups at the primary and disaster-recovery sites are deleted.
Mitigation process?
CERTVU recommends the following:
-
Patch Both Exploited Vulnerabilities Immediately
For Fortinet: upgrade FortiOS to 7.0.17 or above, and FortiProxy to 7.0.20 or 7.2.13 or above. Where immediate patching is not possible, disable the Security Fabric (config system csf) on devices that do not require it, restrict administrative access using trusthost entries and a dedicated management VLAN, and place management interfaces behind a VPN or jump host rather than exposing them to the internet. For Schneider Electric PowerLogic P5 protective relays, apply the vendor's firmware update for CVE-2024-5559 and restrict physical/front-panel access to authorised personnel only. Given confirmed active exploitation, this should be treated as an emergency and actioned without delay.
For further detail, see CISA Advisory AA26-222A: #StopRansomware - Gunra Ransomware.
Reference
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
- https://www.cve.org/CVERecord?id=CVE-2024-5559
- https://www.cve.org/CVERecord?id=CVE-2025-24472
- https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html
- Download advisory (English): CVE-2024-5559 & CVE-2025-24472_Gunra Ransomware