US and South Korea Tie Initial Access to Unpatched Firewalls and VPN Gateways
Critical infrastructure sectors worldwide running unpatched edge devices are being hit by a ransomware group potentially tied to North Korea, warns a joint U.S. and South Korean cybersecurity alert.
See Also: Why Healthcare Leaders Are Rethinking Their Data Strategy Before Scaling AI
The Gunra ransomware-as-a-service operation continues to target known vulnerabilities in VPN gateways and firewall appliances, the Monday alert warns.
Two of the flaws being actively targeted by the attackers to gain initial access are in Fortinet products, for which the vendor issued patches in early 2025, says the joint alert from U.S. government agencies – including Cybersecurity and Infrastructure Security Agency, FBI, NSA and Secret Service – together with the South Korea’s National Police Agency.
Based on posts to its data leak site, the Gunra operation has amassed victims across healthcare, financial services, critical manufacturing, transportation and government services, as well as utilities, retail and other sectors, across every region of the world. The FBI said data exfiltrated by attackers to hold to ransom has “included business-critical documents, databases personally identifiable information (PII) and internal email communications.”
The advisory urges organizations to “prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and remote desktop protocol-exposed infrastructure,” to segment networks to better contain breaches by blocking hackers’ lateral movement inside their network, and to deploy immutable backups.
“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations,” said Chris Butera, CISA’s acting executive assistant director for cybersecurity. He urged all organizations to rapidly apply the recommended mitigations.
Butera also urged critical infrastructure sector organizations to embrace version 2.0 of CISA’s cross-sector cybersecurity performance goals, which refer to common protections it advises implementing to help mitigate adversary’s most often used techniques.
This week’s joint alert follows South Korean government and intelligence authorities on July 30 warning that they were tracking both Gunra and the Lazarus group – a state-sponsored North Korean hacking team – using the same malware and network infrastructure, as well as shared SSH key fingerprints. The alert said both clusters of threat activity exploited the same vulnerabilities in security software that gets installed when using South Korean financial services (see: North Korea’s APT Capabilities Are No Longer State-Exclusive).
Whether one or more Gunra affiliates might be moonlighting Pyongyang government hackers wasn’t clear. In a supplement to the alert, South Korean cybersecurity firm AhnLab said that it “cannot definitively determine” how the two clusters of threat activity might relate to each other. But it nicknamed the campaign “Operation Double Barrel” to highlight how both sets of attackers employed “common attack flows” and overlapping “technical links.”
The Gunra ransomware operation emerged in April 2025. Cybersecurity experts said the initial version of its crypto-locking malware appeared to be based on leaked Conti source code, and only targeted Windows systems. By mid-2025, the group also appeared to be wielding crypto-locking malware against Linux systems.
In January, the group launched a ransomware-as-a-service operation designed to recruit affiliates. It egan branding itself using new aliases, including “Golden Community,” and “further commercialized its platform by actively recruiting penetration testers and ethical hackers to serve as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access,” the FBI said.
After gaining initial access, attackers tied to Gunra wield “multiple stealth and defense impairment techniques to hinder detection and analysis,” including deleting system and access logs, wiping command history, as well as conducting “malicious activities and internal infrastructure reconnaissance during late-night and early-morning hours,” victim time, it said.
Unpatched Edge Gear Gets Popped
The FBI warned Monday it’s continued to see Gunra gaining remote access to victims’ systems by exploiting “credential-exposure and Secure Shell (SSH) access control vulnerabilities in internet-facing VPN gateways.” These include two specific vulnerabilities affecting FortiOS – the operating system that runs FortiGate’s firewalls and secure networking hardware, and virtual machines and cloud computing platforms – and FortiProxy, which is the company’s secure web gateway.
The FortiOS and FortiProxy authentication bypass vulnerabilities “may allow a remote attacker to gain super-admin privileges” either by making a specially crafted request to the Node.js websocket module, or by using proxy requests to CSF, which refers to the cluster synchronization framework in Fortinet’s Security Fabric cybersecurity platform, the vendor said in a January 2025 security alert.
The alert first detailed CVE-2025-24472, an authentication bypass vulnerability in FortiOS 7.0.0 through 7.0.16, FortiProxy 7.0.0 through 7.0.19, and FortiProxy 7.2.0 through 7.2.12 (see: Fortinet Users See Active Zero-Day Warnings Past and Present).
In February 2025, Fortinet updated its security advisory to include CVE-2024-55591, which is an authentication bypass flaw affecting the same software and versions.
Fortinet said that successful attacks enabled hackers to create super-admin accounts and to modify firewall configurations and establish SSL VPN tunnels for ongoing, remote access.
“Our intelligence indicates that multiple ransomware groups have been actively exploiting this vulnerability. Given the critical nature of this vulnerability, we strongly encourage you to apply the patch and take the necessary actions immediately to safeguard your environment,” Fortinet said in an alert dated Feb. 4, 2025.
Shortly thereafter, cybersecurity researchers warned of widespread exploitation, in some cases leading attackers to patch the devices themselves to hide signs of their infiltration and ongoing, remote access to the hardware.
Eighteen months after Fortinet first warned customers to patch the vulnerabilities, CISA and its sister agencies continue to repeat that call in the face of yet more active ransomware attacks, including against critical national infrastructure.
Click Here For The Original Source.
