A joint federal and international cybersecurity advisory is warning organizations about the expanding threat posed by Gunra ransomware, a ransomware-as-a-service operation that has targeted government, critical infrastructure, and private-sector organizations across multiple regions.
The advisory was issued on August 10, 2026, by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency. The agencies said Gunra first appeared in 2025 and expanded into a structured ransomware-as-a-service operation during 2026.
Gunra uses a double-extortion model in which attackers steal sensitive data before encrypting victim systems, then threaten to publish or sell the information if a ransom is not paid.
The advisory states that victims associated with Gunra have appeared across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific. Victim organizations observed on Gunra’s dedicated leak site span healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services.
The FBI first observed Gunra ransomware in April 2025. By January 2026, the operation had launched a formal affiliate program on dark web forums, giving participating criminals access to a management panel, configurable ransomware builders, cross-platform locker payloads, and operational documentation.
Federal investigators also observed the group operating under the name Golden Community as it expanded its ransomware-as-a-service structure. The advisory states that Gunra has been actively recruiting penetration testers and ethical hackers to serve as initial access brokers in exchange for a share of ransom proceeds.
Investigators said Gunra actors primarily gain initial access by exploiting vulnerabilities in Internet-facing systems, including firewall and VPN infrastructure.
The FBI specifically identified exploitation of CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities affecting certain FortiOS and FortiProxy versions. South Korean authorities also observed Gunra actors exploiting credential-exposure and SSH access-control vulnerabilities in Internet-facing VPN gateways.
Once inside a network, Gunra actors have demonstrated extensive lateral-movement and credential-theft capabilities.
The advisory states that the attackers have used tools from the Impacket framework, including psexec.py and smbclient.py, to move laterally through compromised networks using SMB.
In one documented case, the actors obtained administrator access to an SSL-VPN appliance by exploiting default credentials on a system where account lockout protections were not enabled. They then downloaded OpenSSH from attacker-controlled infrastructure to establish persistent tunneling connections into the victim environment.
The attackers later used stolen session information to gain access to internal virtual desktop infrastructure and moved laterally through RDP to systems including a VDI authentication server, an Active Directory server, and virtual desktops used by IT personnel.
The FBI also observed Gunra actors using secretsdump.py against compromised domain controllers to extract password hashes from NTDS files, enabling pass-the-hash and pass-the-ticket attacks against additional privileged systems.
The actors have also manipulated authentication systems directly.
In one victim environment, Gunra operators altered files on a VDI authentication server so that an attacker-selected one-time password would be accepted, creating a persistent method of bypassing multifactor authentication.
In another stage of the intrusion, the actors accessed a Hiware system access control server and stole a symmetric encryption key that allowed them to decrypt stored enterprise server credentials.
The advisory also details efforts by Gunra actors to conceal their activity. Investigators observed them deleting system and network access logs, clearing command histories, and conducting reconnaissance and malicious operations primarily during late-night and early-morning hours between 10 p.m. and 6 a.m.
Gunra’s Windows encryptor is designed to enumerate files and directories across accessible drive letters before targeting user data for encryption.
The malware excludes common system directories and system-critical file extensions while documents, databases, images, archives, and other user-controlled data are selected for encryption.
Before encryption, Gunra actors have also been observed stealing business-critical documents, databases, personally identifiable information, internal emails, and system configuration data.
The FBI observed attackers using a malicious executable identified as main.exe to exfiltrate data from Microsoft OneDrive and SharePoint. In at least one known intrusion, the volume of stolen information reached tens of terabytes before being transferred to the Mega file-sharing service.
The advisory also identifies the use of FileZilla, RClone, WinRAR, 7-Zip, Mimikatz, Impacket, AnyDesk, Google Remote Desktop, MobaXterm, Sliver, and other legitimate or publicly available tools during Gunra operations.
Federal agencies cautioned that the presence of those tools alone does not establish malicious activity because many have legitimate administrative, development, or security uses.
Gunra encrypts victim files using ChaCha20 combined with RSA-4096 encryption. The ransomware has used the .ENCRT extension on encrypted files, while a .CRYPT extension was observed in one July 2025 sample.
After encryption, the malware places a ransom note named R3ADM3.txt in affected directories. Victims are instructed to begin negotiations through a Tor-based portal or qTox within five to seven days.
The FBI said Gunra actors have opened ransom negotiations with demands reaching into the tens of millions of dollars and have attempted to contact company management directly through email to solicit ransom payments.
If payment is not made, the group has threatened to publish or sell stolen datasets through its dedicated leak infrastructure.
Gunra actors have also attempted to prevent victims from recovering without paying.
The advisory states that attackers used Windows Management Instrumentation to delete volume shadow copies before encryption. In one known case, Gunra operators deleted backup and archived data stored at both the victim’s primary data center and disaster recovery center.
The agencies are urging organizations to prioritize patching known exploited vulnerabilities on Internet-facing infrastructure, secure VPN and RDP systems, enforce multifactor authentication, audit privileged accounts, remove unauthorized accounts, segment networks, and maintain offline immutable backups.
Organizations that detect possible Gunra activity are advised to isolate affected systems, preserve forensic evidence, identify compromised accounts, and begin threat hunting before completing full eviction procedures.
The advisory also notes a potentially important recovery issue affecting certain Linux variants.
Researchers identified a weakness in some Gunra Linux ELF ransomware samples that use a predictable pseudorandom number generator. In some cases, defenders may be able to reconstruct encryption keys using file timestamps and recover encrypted information without paying the ransom.
Gunra should be treated as a full enterprise intrusion threat rather than a simple file-encryption event.
Its observed operations include exploitation of Internet-facing vulnerabilities, credential theft, VPN compromise, MFA bypass, session hijacking, lateral movement, cloud-data theft, backup destruction, and ransomware deployment across Windows and Linux environments.
The expansion of Gunra into a ransomware-as-a-service model also increases the potential number of operators capable of using the group’s infrastructure and tooling against additional victims.
For defenders, the central issue is not limited to restoring encrypted files. A compromised organization may also need to determine whether attackers stole credentials, established persistence, accessed cloud data, modified authentication infrastructure, or destroyed recovery systems before ransomware was deployed.
Joint Cybersecurity Advisory AA26-222A, #StopRansomware: Gunra Ransomware — Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and Republic of Korea National Police Agency, August 10, 2026. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



