Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass

U.S. and South Korean intelligence agencies warn Gunra ransomware exploits Fortinet firewall flaws alongside a previously undocumented MFA bypass technique.
Table of Contents
    Add a header to begin generating the table of contents

    U.S. and South Korean intelligence agencies issued a joint warning about Gunra ransomware attacks targeting critical infrastructure sectors worldwide, revealing that the group exploits legacy Fortinet and Schneider Electric vulnerabilities alongside a previously undocumented MFA bypass technique to breach networks across healthcare, financial services, government facilities, and professional organizations globally. The advisory marks the first time both jurisdictions have formally attributed these specific capabilities to the Gunra cluster, confirming that the ransomware group has evolved from episodic encryption attacks into sophisticated infrastructure exploitation operations spanning IT and OT environments.

    Exploitation of Fortinet and Schneider Infrastructure for Initial Access

    Gunra uses leaked Conti code as its ransomware base combined with exploitation of unpatched Fortinet firewall and VPN appliances and Schneider Electric industrial controllers to gain initial access. The group first compromises the network perimeter through Fortinet firewall and VPN vulnerabilities — including the SonicWall SMA1000 flaws also referenced in August 2026 Patch Tuesday advisories — gaining administrative foothold, then pivots through Schneider Electric industrial controllers that connect IT infrastructure to operational technology systems.

    This dual-target approach creates a particularly dangerous attack path: an attacker compromising both network and control equipment can move laterally across corporate networks while simultaneously accessing physical system controls — creating operational risk for critical infrastructure organizations that depend on the continuous functioning of heating, power generation, or water treatment processes controlled by Schneider devices in their industrial environments.

    How the Group Bypasses Multi-Factor Authentication

    After gaining network access, Gunra bypasses MFA through a specific technique against Microsoft 365 and other cloud identity providers — using device code phishing combined with token-relay attacks to obtain valid authentication sessions without user detection. The technique operates through the device code flow in Microsoft 365: an attacker registers a malicious application, triggers a device code challenge, then relays that code through an intermediary session to obtain access tokens completing the authentication flow without the target user ever receiving or entering a verification code.

    Intelligence agencies described this as a significant operational advancement for ransomware groups previously limited to credential phishing against MFA-protected accounts. Organizations should audit Microsoft 365 logs for device code phishing artifacts and enforce conditional access policies that block suspicious device registrations — critical monitoring since the technique produces authentication sessions indistinguishable from legitimate cloud identity provider behavior once tokens are obtained.

    DeadLock Ransomware Adopts Blockchain Infrastructure for Extortion Operations

    In a parallel development, Microsoft Threat Intelligence Team documented that DeadLock ransomware has adopted decentralized infrastructure combining Polygon blockchain smart contracts, Session messenger network, and encrypted cloud storage for victim communications and data leak operations — a significant operational shift from traditional C2-based extortion methods. DeadLock’s recovery ecosystem stores and delivers resources used throughout the extortion process on-chain, making takedown efforts by law enforcement significantly harder than against centralized ransomware infrastructure.

    The group uses Session, a decentralized messaging protocol, for victim contact; Polygon smart contracts to auto-execute ransom demands; and blockchain services for data leak site hosting, essentially operating a ransomware-as-a-service model distributed across web3 infrastructure. This evolution means traditional ransomware takedown coordination strategies — seizing server clusters or blocking domain registrations — become ineffective when the extortion infrastructure exists entirely within blockchain networks and decentralized protocols that cannot be shut down through conventional law enforcement techniques.

    MFA Bypass TTPs and Infrastructure Shifts: What the Gunra DeadLock Advisories Reveal

    The joint U.S.-South Korean intelligence advisory on Gunra and Microsoft ThreatIntel reporting on DeadLock represent two parallel operational shifts in ransomware methodology. Gunra’s device code phishing technique against OAuth 2.0 flows lets operators establish authenticated M365 sessions without triggering user awareness — a capability that bypasses the primary defense most enterprises rely on for identity protection. The group’s simultaneous exploitation of Fortinet firewall/VPN and Schneider Electric industrial controllers creates a dual-vector attack path across IT and OT layers that few organizations have mapped in their own environments.

    DeadLock’s use of Polygon smart contracts combined with Session messenger creates an extortion architecture that cannot be dismantled through traditional server seizure methods. When ransom demands, victim communication, and data leak site hosting all execute across decentralized infrastructure, law enforcement coordination must shift from takedown operations to blockchain tracing — a fundamentally different operational requirement for investigative resources.

    Defensive Implications for Enterprise Networks

    For Gunra: organizations should patch all Fortinet and Schneider Electric appliances; audit for device code phishing artifacts in Microsoft 365 logs; enforce conditional access policies that block suspicious device registrations; and hunt for legacy Conti-style encryption patterns on network shares. For DeadLock: monitor Polygon blockchain for ransom payment transactions linked to known DeadLock wallet addresses and coordinate with law enforcement on blockchain tracing approaches rather than server takedown coordination strategies. Both threat clusters continue operational expansion, making proactive defense the only effective countermeasure given their hardened infrastructure against traditional disruption tactics.

    Related Posts