VORANT. Threat Intelligence Sign in Get the full feed

Gunra Ransomware Matures Into RaaS Platform

high threat healthcarefinancial-servicesmanufacturingtransportationgovernment-nationalenergyeducationmediaretailnon-profit

CISA and FBI warn that Gunra, a Conti-derived ransomware group, has launched a RaaS affiliate program and is exploiting Fortinet flaws for double-extortion attacks worldwide.

A joint advisory from FBI, CISA, DC3, NSA, USSS, and South Korea's KNPA details the evolution of Gunra ransomware, which first appeared in April 2025 as a double-extortion variant built on leaked Conti source code. By early 2026 the group had matured into a structured ransomware-as-a-service operation, rebranding some activity as "Golden Community," recruiting affiliates and initial access brokers (including penetration testers) via dark web forums, and offering a management panel and cross-platform locker builder. Victims span healthcare, financial services, manufacturing, transportation, government, utilities, education, media, retail, and nonprofit sectors across the Americas, Europe, MEA, and APAC.

Gunra actors gain initial access primarily by exploiting known Fortinet authentication bypass vulnerabilities (CVE-2024-55591, CVE-2025-24472) and SSH/VPN credential weaknesses, then use Impacket tools (psexec.py, secretsdump.py, smbclient.py) for lateral movement and credential dumping via NTDS extraction. Observed intrusions show sophisticated tradecraft including SSL-VPN session hijacking, MFA bypass via authentication file tampering, and theft of encryption keys to decrypt stored server credentials. The Windows encryptor uses ChaCha20+RSA-4096 for fast multi-threaded encryption (.ENCRT extension), deletes shadow copies and backups, and exfiltrates data via OneDrive/SharePoint abuse, Mega, and tools like RClone and FileZilla, with some incidents involving tens of terabytes of stolen data.

Notably, researchers identified a cryptographic weakness in Gunra's Linux ELF variant (.GNRA extension): encryption keys are seeded with a predictable time(NULL)-based PRNG, allowing victims to potentially reconstruct keys and recover files without paying ransom. The advisory recommends prioritized patching of internet-facing VPN/RDP infrastructure, offline immutable backups, network segmentation, and MFA enforcement to mitigate the threat.

Mentioned in this report

Vulnerabilities CVE-2024-55591KEVCVE-2025-24472KEV
Threat actors gunra
Malware Gunra

Detection guidance

1 detection artefacts for this report are available to subscribers.

Source reporting: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free