THREAT SUMMARY
Category: Ransomware-as-a-Service / Double Extortion / Critical Infrastructure Security
Affected Products: Windows Systems, Linux Systems, FortiOS, FortiProxy, VPN Gateways, SSL-VPN Appliances, RDP Infrastructure, VDI Environments, Active Directory, Domain Controllers, Microsoft OneDrive, Microsoft SharePoint, Database Servers, Network-Attached Storage and Backup Infrastructure
CVEs: CVE-2024-55591, CVE-2025-24472
Primary Risks: Unauthorized Remote Access, Authentication Bypass, Credential Theft, MFA Bypass, Session Hijacking, Lateral Movement, Data Exfiltration, File Encryption, Backup Destruction, Operational Disruption, Public Disclosure of Stolen Information, Financial Extortion
Threat Status: Confirmed Active and Expanding Ransomware Activity
Affected Environment: Government, Critical Infrastructure, Healthcare, Financial Services, Insurance, Manufacturing, Construction, Transportation, Logistics, Utilities, Academia, Media, Communications, Retail, Professional Services and Nonprofit Organizations
Attack Vectors: Exploitation of Internet-Facing Devices, Vulnerable VPN Gateways, Exposed Credentials, Default Credentials, Weak Account-Lockout Controls, SSH Access-Control Weaknesses, Stolen Sessions and Compromised Administrative Accounts
CISA Action: Joint Cybersecurity Advisory AA26-222A Issued With Technical Findings, Mitigations, MITRE ATT&CK Mappings and STIX Indicators of Compromise
The Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service and Republic of Korea’s National Police Agency have issued a joint advisory warning government agencies, critical infrastructure operators and private organizations about the expanding Gunra ransomware threat.
The advisory, identified as AA26-222A, was released on August 10, 2026, through the federal #StopRansomware initiative. It documents Gunra’s development from a ransomware variant first observed by the FBI in April 2025 into a structured ransomware-as-a-service operation supporting attacks across Windows and Linux environments.
Gunra is based on or significantly influenced by the Conti ransomware source code leaked in 2022. The operation established a dedicated leak site on the Tor network shortly after its emergence and expanded into a formal affiliate program in January 2026.
The RaaS program provides affiliates with a management panel, configurable ransomware builder, cross-platform locker payloads and supporting documentation. The FBI also observed the operation using the name Golden Community as it expanded its criminal infrastructure.
Gunra has attempted to recruit penetration testers and ethical hackers to serve as initial-access brokers. Recruits are offered a share of ransom proceeds in exchange for unauthorized access to enterprise networks, creating another path through which compromised credentials or established access may reach Gunra affiliates.
The operation uses double extortion by stealing sensitive information before encrypting the victim’s systems. Gunra actors threaten to publish or sell the stolen material through a dedicated leak site if the victim refuses payment.
Victims are directed to a customized Tor-based negotiation portal and assigned a client identification number and initial password. Gunra actors then instruct victims to continue negotiations through qTox, an encrypted communications application, and commonly impose a deadline of five to seven days.
The FBI observed negotiations beginning with demands reaching tens of millions of dollars. The actors have also attempted to contact management personnel at victim organizations by email to increase pressure and solicit payment.
Organizations displayed on Gunra’s leak site span the Americas, Europe, the Middle East, Africa and the Asia-Pacific region. Affected sectors include healthcare and public health, financial services, insurance, critical manufacturing, construction, transportation, logistics, government services and facilities, utilities, academia, media and communications, retail, professional services and nonprofit organizations.
The agencies have not attributed Gunra to a named state sponsor or identified a single individual directing the operation. The affiliate structure means that different intrusions may involve different access methods, tools, timelines and technical decisions while using the same Gunra ransomware and extortion infrastructure.
Vulnerability Details
CVE-2024-55591 — FortiOS and FortiProxy
Vulnerability: Authentication Bypass Using an Alternate Path or Channel
CVE-2024-55591 is an authentication-bypass vulnerability affecting specified FortiOS and FortiProxy versions.
The FBI observed Gunra actors exploiting the vulnerability against internet-facing devices, including firewall and VPN appliances. Authentication bypass can allow an attacker to reach protected functions without completing the security process intended to verify the user’s identity.
Exploitation of CVE-2024-55591 can support the creation of a malicious persistent account named forticloud-sync on vulnerable Fortinet devices. The account can be assigned superuser privileges and a hard-coded password, creating a privileged access point that may remain after the initial exploitation event.
Installing the applicable security update does not automatically remove accounts, sessions, configuration changes or persistence established before remediation. Organizations must examine affected systems for the forticloud-sync account and review administrative records for unauthorized changes.
The advisory does not provide a complete list of affected product versions within its narrative. Organizations must compare deployed FortiOS and FortiProxy versions with current vendor security guidance and identify systems exposed during the period before remediation.
CVE-2025-24472 — FortiOS and FortiProxy
Vulnerability: Authentication Bypass Using an Alternate Path or Channel
CVE-2025-24472 is a separate authentication-bypass vulnerability affecting specified FortiOS and FortiProxy versions.
The FBI identified this vulnerability among the known weaknesses exploited by Gunra actors against internet-facing infrastructure. The vulnerability can expose administrative functions when a vulnerable system accepts an alternate authentication path or channel that does not properly enforce access controls.
CVE-2025-24472 has also been connected to the creation of the malicious forticloud-sync account on vulnerable Fortinet devices. The presence of that account should be treated as a potential indicator of compromise requiring immediate investigation.
Organizations should not assume that patching CVE-2025-24472 resolves every consequence of prior exploitation. Security teams must review administrative sessions, scheduled tasks, account creation, configuration changes, VPN activity, authentication records and connections from the affected device into internal networks.
The Republic of Korea’s National Police Agency observed additional Gunra access involving exposed credentials and SSH access-control weaknesses in internet-facing VPN gateways. In one victim environment, the actors obtained access to an SSL-VPN administrator account by exploiting default credentials where account-lockout protections were absent.
Gunra actors downloaded OpenSSH from an attacker-controlled server and used it to establish tunnels between compromised systems. These connections allowed the actors to maintain access and communicate across the victim’s environment.
After compromising a workstation used by a network administrator, the actors entered an SSL-VPN administrative console and identified an unused account capable of accessing both internet-facing and internal corporate networks. They altered the account to bypass a mandatory password-change requirement and used it for malicious activity.
Stolen session information was used to enter an internal virtual desktop infrastructure environment. The actors then moved through RDP to the VDI authentication server, internal Active Directory server and virtual desktops assigned to information technology personnel.
The FBI observed Gunra actors using the Impacket tools psexec.py, smbclient.py and secretsdump.py. These tools supported lateral movement through Server Message Block, credential extraction from compromised domain controllers and theft of password hashes from the NT Directory Services file.
Stolen hashes can support pass-the-hash and pass-the-ticket activity against privileged systems. The actors also manipulated SSL-VPN traffic-control functions to collect credentials and session information from users authenticating through a corporate VDI portal.
In one intrusion, Gunra actors altered authentication-processing files so that a designated one-time password would be accepted by the VDI portal. This created an unauthorized method of bypassing multi-factor authentication.
The actors also accessed a Hiware system-access-control server through SSH and stole a symmetric encryption key. That key allowed them to decrypt enterprise-server passwords stored in the system’s database and obtain credentials associated with additional servers.
Gunra performs reconnaissance across accessible drive letters from A through Z before encryption. The Windows binary uses native operating-system application programming interfaces to enumerate files and directories, exclude selected system files and place targeted user information into an encryption queue.
The ransomware avoids specified Windows directories and system-critical extensions while prioritizing documents, databases, images, archives and other user information. This selective process can preserve enough operating-system functionality to display ransom instructions while damaging the information most valuable to the victim.
Operational Impact
- Unauthorized access to internet-facing firewall and VPN appliances
- Creation of malicious privileged accounts
- Compromise of administrative workstations
- Theft of domain credentials and password hashes
- Pass-the-hash and pass-the-ticket activity
- Hijacking of authenticated user sessions
- Bypass of multi-factor authentication
- Persistent SSH tunneling into compromised environments
- Lateral movement through SMB and RDP
- Compromise of Active Directory and domain controllers
- Unauthorized access to VDI infrastructure
- Collection of business-critical documents
- Theft of personally identifiable information
- Collection of internal email communications
- Exfiltration from Microsoft OneDrive and SharePoint
- Theft of system and network configuration records
- Compromise of database servers and network-attached storage
- Encryption of Windows and Linux systems
- Deletion of volume shadow copies
- Destruction of primary and disaster-recovery backups
- Public disclosure or sale of stolen information
- Service interruption and operational shutdown
- Financial losses and recovery expenses
- Reputational, contractual and regulatory exposure
Gunra actors have collected business documents, databases, personally identifiable information, internal email communications and system-configuration records before encryption. In one documented intrusion, the amount of information removed from the victim’s environment reached tens of terabytes.
The FBI observed Gunra using a malicious executable named main.exe to remove information from Microsoft OneDrive and SharePoint. The actors also created compressed archives and transferred stolen material through the Mega file-sharing service.
Publicly available tools associated with observed activity include FileZilla, Amass, RClone, Sliver, 7-Zip, WinRAR, DBeaver, Mimikatz and Impacket. The presence of one of these tools does not independently prove malicious activity because each may have legitimate administrative or security uses. Execution context, user identity, timing, command history, file location and network destination must support any conclusion that the tool was controlled by Gunra actors.
Gunra uses multithreaded processing and combined ChaCha20 and RSA-4096 encryption to encrypt multiple files rapidly. Encrypted files commonly receive the .ENCRT extension. One documented sample used .CRYPT.
After encrypting a directory, the ransomware places a ransom note identified as R3ADM3.txt within it. Victims are directed to begin negotiations through Tor or qTox and send cryptocurrency to designated wallet addresses.
The actors have used Windows Management Instrumentation to delete volume shadow copies before encryption. In one documented incident, Gunra destroyed backup and archived information stored at both the primary data center and the disaster-recovery center.
The extent of the operational damage depends on the systems reached before encryption, the privileges obtained, the amount of information removed, the separation of backup infrastructure and the victim’s ability to restore essential services. Recovery from backup cannot reverse the loss of confidentiality after stolen information has left the network.
Federal Response
CISA, the FBI, DC3, NSA, USSS and KNPA issued AA26-222A to provide organizations with technical findings, observed tactics, indicators of compromise, incident-response instructions and defensive guidance connected to Gunra ransomware.
The advisory maps Gunra activity to the MITRE ATT&CK for Enterprise framework, version 19.1. The documented behavior covers initial access, execution, persistence, privilege escalation, credential access, lateral movement, defense impairment, discovery, collection, command and control, exfiltration and impact.
CISA also released machine-readable STIX XML and STIX JSON packages containing Gunra indicators. Those files identify 17 associated IP addresses, four domains, including three Tor addresses, four negotiation email addresses, four malicious executable hashes, two exploited CVEs and additional technical relationships.
The STIX packages allow security teams to ingest indicators into security information and event management platforms, endpoint detection systems, firewalls, DNS-monitoring systems and threat-hunting tools. Historical infrastructure may no longer remain under actor control, so indicators should be investigated and validated before blocking or attributing activity.
The agencies are seeking boundary logs containing communications with foreign IP addresses, ransom notes, actor communications, cryptocurrency wallet information, decryptor files, benign encrypted-file samples, transaction identifiers, infection dates, detection dates, initial-access details and assessments of operational impact.
The agencies do not encourage ransom payment. Payment does not guarantee restoration of encrypted files, deletion of stolen information or an end to further demands. Ransom proceeds can also finance additional criminal activity and reinforce the economic model supporting future attacks.
Organizations can report incidents to the FBI Internet Crime Complaint Center, a local FBI field office, a local U.S. Secret Service field office or CISA. CISA accepts reports through its Incident Reporting System, its 24-hour Operations Center at contact@cisa.dhs.gov and 1-844-SAY-CISA. South Korean organizations can report incidents to KNPA through its cybercrime reporting system or by calling 112.
KEV Catalog Continues to Expand
CISA’s advisory identifies CVE-2024-55591 and CVE-2025-24472 as known vulnerabilities exploited by Gunra actors against affected FortiOS and FortiProxy deployments.
Known exploitation changes the operational priority of a vulnerability. A theoretical weakness may be scheduled according to normal maintenance procedures, but an exploited vulnerability affecting an internet-facing security appliance requires accelerated remediation and compromise assessment.
The exploitation of Fortinet edge devices demonstrates the value attackers place on systems positioned between public networks and protected internal environments. Successful access to a firewall or VPN appliance can expose administrative controls, authenticated sessions, internal routes and credentials capable of supporting deeper movement.
Organizations should treat KEV remediation as more than an update-management function. A security update can close the vulnerable pathway, but it cannot determine whether an attacker entered before the correction was applied.
A complete response requires historical review of system records, administrative activity, account creation, sessions, scheduled tasks, configuration changes and connections into internal resources. Systems that were publicly exposed while vulnerable may require credential rotation and broader forensic examination.
The joint advisory does not announce newly assigned federal remediation dates for CVE-2024-55591 or CVE-2025-24472. Organizations should follow current CISA and vendor requirements applicable to their assets while treating the documented Gunra exploitation as evidence of urgent risk.
Defensive Guidance
- Identify every FortiOS and FortiProxy deployment.
- Document installed versions, configurations and network exposure.
- Apply security updates for CVE-2024-55591 and CVE-2025-24472.
- Prioritize internet-facing firewall, VPN and RDP infrastructure.
- Search Fortinet devices for the unauthorized
forticloud-syncaccount. - Review newly created, modified, dormant and unrecognized accounts.
- Remove default credentials and enforce account-lockout protections.
- Require multi-factor authentication for VPNs, webmail and privileged accounts.
- Review authentication-processing files for unauthorized modifications.
- Invalidate suspicious sessions and rotate potentially exposed credentials.
- Examine domain controllers for evidence of credential dumping.
- Review NTDS access and pass-the-hash or pass-the-ticket activity.
- Monitor use of
psexec.py,smbclient.pyandsecretsdump.py. - Investigate unexpected SMB, RDP and SSH activity.
- Review VPN appliance logs for unauthorized administrative sessions.
- Search for unapproved OpenSSH tunnels and external connections.
- Examine cloud records for abnormal OneDrive and SharePoint collection.
- Investigate unexpected archive creation and large outbound transfers.
- Monitor execution of FileZilla, RClone, 7-Zip, WinRAR and related utilities.
- Review privileged activity occurring between 10:00 p.m. and 6:00 a.m.
- Detect deletion of access logs and command histories.
- Monitor WMI activity involving volume shadow copies.
- Segment administrative, production, VDI, database and storage networks.
- Isolate backup systems from production credentials and network paths.
- Maintain multiple offline or immutable backup copies.
- Test restoration procedures before an incident occurs.
- Preserve ransom notes, encrypted files, timestamps and relevant logs.
- Load the CISA STIX indicators into appropriate monitoring systems.
- Validate indicators before blocking historical infrastructure.
- Isolate compromised hosts after preserving required evidence.
- Disable malicious accounts and secure legitimate privileged accounts.
- Use CISA’s Eviction Strategies Tool to develop a coordinated removal plan.
- Test security controls against the documented MITRE ATT&CK techniques.
- Continue monitoring after remediation for persistent access.
- Report confirmed incidents to the appropriate federal authorities.
For Linux systems affected by the Gunra ELF variant, responders should preserve encrypted .GNRA files, original timestamps, ransom notes and system logs. A weakness identified in the variant’s encryption process may permit mathematical reconstruction of encryption keys because it uses a predictable time-seeded pseudorandom number generator. Altering timestamps or discarding encrypted material could remove information required for recovery.
Defenders should preserve sufficient evidence before beginning actor eviction. Immediate removal without understanding the full access path may leave secondary accounts, stolen sessions, modified authentication files or persistent tunnels undiscovered.
Remediation should address the exploited vulnerability, unauthorized access and every downstream system reached through the compromised device. Restoring encrypted information without investigating exfiltration can leave the organization unaware of what information was stolen and exposed.
Forecast — 30 Days
- Continued scanning for vulnerable internet-facing FortiOS and FortiProxy systems
- Additional exploitation attempts against unpatched VPN and firewall appliances
- Continued recruitment of affiliates and initial-access brokers
- Expansion of attacks across Windows and Linux environments
- Greater use of stolen credentials and authenticated sessions
- Continued targeting of healthcare, government and critical infrastructure
- Additional theft from cloud-storage and collaboration platforms
- Increased attempts to destroy primary and disaster-recovery backups
- Continued publication or sale of stolen information through Gunra’s leak site
- Greater use of automated indicator ingestion and threat hunting
- Expanded review of historical VPN and administrative activity
- Additional identification of malicious accounts and persistent tunnels
- Continued pressure on victims through short negotiation deadlines
- Further refinement of cross-platform ransomware payloads
- Increased validation of recovery procedures and immutable backups
TRJ Verdict
Gunra is not limited to encrypting files after a single compromised endpoint. The operation is designed to exploit exposed security infrastructure, capture privileged access, move through trusted systems, steal large volumes of information, destroy recovery options and apply financial pressure through public disclosure.
The transition to a ransomware-as-a-service model expands the threat by allowing multiple affiliates to conduct attacks through a shared criminal platform. Differences between affiliates may change the opening method or toolset, but the final objective remains the theft and encryption of information for financial extortion.
CVE-2024-55591 and CVE-2025-24472 require immediate attention because the FBI observed Gunra actors exploiting them against internet-facing FortiOS and FortiProxy systems. Patching is necessary, but organizations must also determine whether those systems were accessed before remediation.
The strongest defense requires control of the entire attack path: exposed edge devices, administrative accounts, active sessions, identity systems, internal segmentation, cloud storage, backup infrastructure and outbound transfers. Failure at any one point can allow a foothold to develop into a network-wide compromise.
Every organization operating affected Fortinet systems or exposed remote-access infrastructure should review its environment promptly. Gunra’s confirmed activity, global victim profile, cross-platform development and established extortion infrastructure show that delayed remediation can create a direct path from one vulnerable device to stolen information, destroyed backups and widespread operational disruption.
Federal Bureau of Investigation; Cybersecurity and Infrastructure Security Agency; Department of Defense Cyber Crime Center; National Security Agency; U.S. Secret Service; and Republic of Korea’s National Police Agency — Joint Cybersecurity Advisory AA26-222A, #StopRansomware: Gunra Ransomware, August 10, 2026. ( Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



