Three Ways In, All of Them Known

Gunra didn't even write their own software. It's built from code that leaked out of a different ransomware gang years ago. They took someone else's tool, renamed it, and started using it. And they're getting into real companies with it, because the way in was already open.

The federal government's cybersecurity agency — CISA, short for the Cybersecurity and Infrastructure Security Agency — published a warning this month about a ransomware group called Gunra, working alongside partner agencies overseas. If you haven't run into the term: ransomware is software that locks up all your files and demands payment to unlock them. Gunra does the modern version, which is worse. They lock up your files and quietly take a copy first. Then if you refuse to pay, they threaten to publish everything they took. Paying to get your files back doesn't solve it, because they still have the copy. They've hit organizations across ten industries on four continents, including healthcare, manufacturing, and financial services. Most of the coverage focuses on their software. We'd point you somewhere else in the document — the section explaining how they actually get in. It's the only part of a warning like this that tells you something you can act on. The technical part — you can skip this box CISA lists three initial access methods: exploitation of CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities in Fortinet's FortiOS and FortiProxy; compromised VPN gateway credentials; and internet-exposed RDP infrastructure. Both CVEs appear on CISA's Known Exploited Vulnerabilities catalog. What that actually means Three ways in, in plain English. One — a firewall that needed an update. A firewall is the device sitting between your office network and the internet. Fortinet, one of the larger firewall manufacturers, had a flaw that let attackers walk straight past the login screen without a password. Fortinet released a fix in early 2025. Businesses that installed it are fine. Businesses that didn't are still wide open, more than a year later. For transparency: we don't deploy Fortinet equipment for our clients, so we have no stake in this either way. We're pointing it out because it's the single most useful fact in the warning — if you have one of these, you need to know it's you. Those "CVE" numbers in the box are just catalog numbers. Every known software flaw gets one, like a case number. The only thing worth knowing about these two is that the government keeps a separate list of flaws criminals are actively using right now, and both are on it. Two — passwords that leaked somewhere else. Someone used the same password for their work remote access that they'd used on some other website. That website got breached, the password ended up in a collection that circulates online, and it still worked. Three — Remote Desktop left open to the internet. Remote Desktop, usually shortened to RDP, is the built-in Windows feature that lets you sign in to your office computer from home. Useful. But if it's switched on and reachable from the open internet, anyone in the world can find it — and there are automated tools that do nothing but scan the entire internet looking for exactly that. That's the full list. A missed update, a reused password, and a door left unlocked. Why we think this is worth your time There's a version of cybersecurity marketing — and our industry produces an enormous amount of it — where every threat is advanced, every criminal is a genius, and the only sensible response is to buy something expensive. This warning doesn't support that story at all. Gunra didn't even write their own software. It's built from code that leaked out of a different ransomware gang years ago. They took someone else's tool, renamed it, and started using it. And they're getting into real companies with it, because the way in was already open. CISA's own list of recommended fixes is almost boringly familiar: keep internet-facing systems updated, keep backups somewhere disconnected that can't be altered, separate your network so a break-in in one place doesn't spread everywhere, and turn on MFA. That list has barely changed in ten years. Not because nobody's paying attention, but because the basics really are the basics. Most companies that get hit weren't beaten by something clever. They were running something out of date, and it wasn't anyone's specific job to catch it. What we'd actually do If you read the above with a slightly uncomfortable feeling, here's the short honest list. Find out whether anyone outside your building can reach your office computers. Most owners we speak with have never been told either way. Find out when your firewall's software was last updated — not when the subscription was renewed, when the software was actually updated. Those get confused constantly. Confirm MFA is on for everyone's email, not just the people who volunteered. Then open an actual file from your backup and see how long it takes, because a backup nobody has ever tested isn't really a backup yet. None of that requires buying anything. It requires somebody to own it. That's the part small businesses genuinely struggle with, and it isn't a failing. It's what happens when the person handling the computers is also handling four other jobs. But the distance between "we have backups" and "we opened one last quarter" is exactly the space these groups work in. The original warning is linked above. It's clearer than most, and the section on how they get in takes about two minutes to read.