A joint advisory from the FBI, CISA, NSA, the Department of Defense Cyber Crime Center, and South Korean cybersecurity agencies has confirmed that Gunra ransomware operators found a way around one of the most trusted enterprise security tools: multi-factor authentication. Rather than stealing a one-time code or phishing a login session, Gunra's affiliates rewrote authentication files directly on victim servers, effectively disabling MFA protections from the inside before deploying encryption and stealing data.
The advisory, issued this month, marks one of the clearer public confirmations that ransomware-as-a-service groups are no longer treating MFA as an obstacle they need to trick. They are treating it as infrastructure they can simply reconfigure once they have gained a foothold.
How Gunra Sidestepped Server-Level MFA
According to the advisory, Gunra affiliates have been exploiting known vulnerabilities in Fortinet firewall and VPN appliances, along with flaws in Schneider Electric systems, to gain initial access to government, critical infrastructure, and enterprise networks. Once inside, rather than attempting to defeat MFA at the login prompt, attackers went after the authentication configuration files stored on the server itself.
By modifying those files at the source, Gunra operators were able to disable or bypass the MFA checks that would normally stop unauthorized logins, all without ever needing a victim's second factor. This is a meaningful distinction from typical MFA-bypass techniques like SIM swapping or push-notification fatigue attacks, which target the user. Gunra's approach targets the infrastructure that enforces the policy in the first place, which means the flaw is architectural rather than behavioral. Patching known vulnerabilities in edge devices like firewalls and VPN appliances, the entry points the advisory says Gunra relies on, remains the most direct way organizations can close this door before it opens.
Gunra operates as ransomware-as-a-service, meaning the core malware is built and maintained by one group while affiliates carry out individual attacks, often reusing leaked code from earlier ransomware families. That structure has helped the operation expand quickly across sectors and geographies since the advisory notes it has already hit government, healthcare, and critical infrastructure targets in multiple countries.
A Silver Lining in the Linux Variant
The advisory also points to a notable weakness in Gunra's Linux-based encryptor. Researchers found that the encryption process leaves behind file timestamp artifacts that can, in some cases, be used to reconstruct the decryption keys without paying the attackers anything. For organizations running Linux servers hit by this specific variant, that opens a path to recovering encrypted data through forensic analysis rather than negotiation with a criminal group.
This kind of implementation flaw is not uncommon in ransomware families that reuse or adapt leaked code, and it does not mean every Gunra victim can recover for free. The Windows-side encryptor does not appear to share the same weakness, and organizations should treat any recovery attempt as a job for experienced incident responders rather than a do-it-yourself fix. Still, it is a rare piece of good news in a ransomware landscape where victims are usually left choosing between paying or rebuilding from backups.
That choice matters because the evidence increasingly shows paying does not reliably solve the problem. A Proofpoint survey found that paying ransomware gangs backfires often, with many organizations reporting they still lost data, faced repeat attacks, or never received usable decryption tools even after payment. The Gunra advisory reinforces that pattern: the safest bet is prevention and recoverability, not negotiation.
What This Means for You
Most readers of this advisory will not be directly targeted by Gunra, but the underlying lesson applies broadly. MFA is a critical layer of defense, but it is not infallible, especially when attackers can reach the server-side configuration that enforces it. If you manage IT systems for a business, hospital, school, or local government agency, this advisory is a signal to check whether your firewall and VPN appliance firmware are current, since Gunra's initial access relies heavily on known, patchable vulnerabilities.
For everyday users, the takeaway is less about this specific ransomware family and more about how you handle your own data. Keeping regular, offline backups of important files remains one of the few defenses that works regardless of how an attacker gets in. How long you retain copies of sensitive files, and where, also affects your exposure if a service you use is ever breached; understanding your own data retention habits, and those of the platforms you rely on, is a practical step toward limiting what any single breach can expose.
Key Takeaways
Organizations running exposed Fortinet or Schneider Electric equipment should prioritize patching immediately, since that is the documented entry point for Gunra intrusions. IT teams should audit server-side authentication configurations for unauthorized changes rather than assuming MFA is working simply because it is enabled. Linux administrators hit by Gunra should consult incident response professionals before assuming files are permanently lost, given the timestamp-based recovery flaw described in the advisory. And for everyone else, this advisory is another reminder that Gunra ransomware and groups like it succeed most often against outdated infrastructure, making patch management and backup discipline more valuable than any single security tool.




