How Fortinet Weaknesses Fuel the Attack
A new ransomware‑as‑a‑service group known as Gunra has begun targeting critical infrastructure worldwide. The gang leverages leaked Conti source code and unpatched Fortinet firewall and VPN vulnerabilities to infiltrate networks, often bypassing multi‑factor authentication (MFA). Reports of successful attacks emerged in early June 2024, affecting utilities, transport operators, and government agencies.
Latest news
The iPhone 18 Pro is anticipated to be unveiled in just a few weeks. Apple typically holds its major product launches in the autumn.
US Smartphone Sales Drop Amid Rising Costs
Farmer Loses Entire Crop After Following AI Herbicide Advice
Mistral Platform to Host External AI Models, Starting with Z.ai's GLM-5.2Gunra’s operators appear to combine old, publicly disclosed Fortinet flaws with sophisticated credential‑stealing tools. By chaining a CVE‑2022‑40684 exploit with a custom script that intercepts MFA tokens, the attackers gain persistent access and deploy ransomware payloads. Researchers say the group’s tactics reflect a shift toward „low‑tech” vulnerabilities that many organizations still overlook. The reuse of Conti code also suggests a shared development pipeline among ransomware crews, lowering the barrier to entry for newer actors.
Security analysts at Mandiant observed that Gunra repeatedly exploits the FortiOS SSL‑VPN buffer overflow disclosed in 2022. Although patches exist, many victims have delayed updates, leaving the gateway exposed. Once inside, the gang uses a man‑in‑the‑middle approach to capture one‑time passcodes sent to users’ devices. „The attackers are effectively neutralizing MFA by replaying intercepted tokens,” explained Mandiant senior researcher Lena Ortiz. The technique allows them to move laterally without triggering typical alerts tied to credential misuse.
Why Is Critical Infrastructure at Greater Risk?
Fortinet’s recent advisory warned that older firmware versions remain vulnerable to the same code execution path. Yet, a survey by the SANS Institute found that over 30 % of surveyed organizations still run outdated FortiOS releases. This lag creates a fertile hunting ground for groups like Gunra, which can automate exploitation across thousands of IP addresses.
Critical sectors rely heavily on legacy systems that often cannot be patched quickly. When a utility’s remote access portal is compromised, attackers can shut down power distribution or manipulate SCADA controls. In a recent incident, a water treatment plant in the Midwest suffered a ransomware lockout after Gunra breached its VPN using the Fortinet flaw. The plant’s operators reported a three‑day outage and costly recovery efforts.
Experts warn that the combination of known vulnerabilities and MFA bypasses amplifies the threat landscape. „Attackers no longer need zero‑day exploits; they can chain existing bugs with credential theft,” noted cyber‑security professor Dr. Amir Patel of Georgetown University. This approach reduces operational complexity for the gang while increasing the potential impact on high‑value targets.
The fallout from Gunra’s campaign is already prompting a reassessment of security priorities. Organizations are urged to accelerate patch deployment, enforce hardware‑based MFA, and segment network access to limit lateral movement. As ransomware services continue to commodify sophisticated tools, defenders must adopt a layered strategy that addresses both software flaws and human factors.
Frequently Asked Questions
What specific Fortinet vulnerability does Gunra exploit? Gunra primarily targets CVE‑2022‑40684, a buffer overflow in FortiOS SSL‑VPN that enables remote code execution when unpatched.
Can multi‑factor authentication still protect against this technique? MFA adds a layer of defense, but if attackers intercept one‑time tokens, they can bypass it. Hardware‑based authenticators reduce this risk.
What steps should organizations take immediately? Apply the latest FortiOS patches, replace software‑based MFA with hardware tokens, and isolate critical systems from internet‑facing VPNs.
Comments
Leave a comment