At a glance
| Malware family | Gunra ransomware (RaaS, Conti-derived) |
| Threat actor | Gunra operators and affiliates, also branded Golden Community |
| Targets | Government and critical infrastructure across five regions |
| Delivery vector | Exploited internet-facing VPN and firewall flaws |
| Key capabilities | Double extortion, MFA bypass, data theft, encryption |
| Source | CISA joint advisory AA26-222A |
TL;DR
Six agencies issued a joint warning about Gunra ransomware on August 10, 2026. The group runs a ransomware-as-a-service operation built on leaked Conti code. It steals data, encrypts systems, and pressures victims through a leak site.
Delivery
Gunra affiliates break in through exposed edge devices. The FBI observed exploitation of two FortiOS authentication bypass flaws, CVE-2024-55591 and CVE-2025-24472. Attackers also abused weak or exposed VPN credentials.
The advisory is blunt about the entry point. It urges defenders to “prioritize patching known exploited vulnerabilities in internet-facing systems.” VPN gateways and RDP-exposed servers top that list.
Gunra runs as a business. As of January 2026, it launched a formal affiliate program on dark web forums. Affiliates get a management panel, a ransomware builder, and cross-platform payloads. The group even recruits penetration testers as initial access brokers.
Infection chain
Once inside, Gunra actors move fast and quietly. They dump credentials from domain controllers to enable pass-the-hash attacks. Then they pivot across the network using RDP and SMB shares.
The actors also hunt for stored secrets. In one case, they stole a symmetric encryption key from a Hiware access control server. That key unlocked passwords for many enterprise accounts at once.
A server-level MFA bypass
One technique stands out. For one victim, the actors edited authentication files on a VDI portal server. That change made a chosen one-time password always succeed. As a result, the attackers held a persistent backdoor that defeated multi-factor authentication.
Attribution here is confirmed, not suspected. The FBI and KNPA directly observed this Gunra ransomware activity during investigations.
Command, control, and data theft
Gunra follows a double-extortion model. Before encrypting, the actors steal business data, PII, and internal email. The advisory notes exfiltrated volumes reaching tens of terabytes for at least one victim.
For exfiltration, the group used cloud services and file-sharing sites. A custom tool pulled data from OneDrive and SharePoint. Other stolen archives went to the Mega service and over FTP.
Encryption and pressure
The Windows encryptor uses ChaCha20 with RSA-4096. It then drops a ransom note in every folder. Victims get five to seven days to negotiate through a Tor portal or an encrypted chat app. You can read the full CISA Gunra ransomware advisory for the complete technical breakdown.
To block recovery, the actors delete volume shadow copies before encrypting. In one case, they wiped backups at both the primary and disaster-recovery sites. Ransom demands started in the tens of millions of dollars.
Victims span many sectors and regions. The list includes healthcare, finance, manufacturing, transportation, government, and utilities. Reported victims appear across the Americas, Europe, the Middle East, Africa, and Asia-Pacific.
Defense and detection guidance
Patching comes first. Close the known FortiOS flaws and other internet-facing bugs. Next, keep offline, immutable backups in a separate location.
Network segmentation limits how far an intruder can spread. Strong MFA and audited admin accounts add more friction. Defenders should also watch for the open-source tools Gunra favors, such as Rclone and Impacket.
One hopeful note
The Linux variant has a flaw. Researchers found its keys use a weak, time-seeded random generator. Therefore, some victims may rebuild keys from file timestamps and recover data without paying.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.