#StopRansomware: CISA Details Gunra Ransomware Operations
CISA and international partners have issued a joint advisory detailing the Gunra ransomware, a RaaS variant that emerged in 2025 and expanded its operations in 2026, targeting critical infrastructure and government organizations.

A new joint Cybersecurity Advisory from CISA and international partners highlights the growing threat posed by the Gunra ransomware, a sophisticated variant that has evolved into a ransomware-as-a-service (RaaS) operation. First observed in April 2025, Gunra rapidly expanded its reach by early 2026, establishing a structured RaaS affiliate program advertised on dark web forums. This program provides financially motivated cybercriminals with access to a management panel, a configurable ransomware builder, and cross-platform payloads, significantly lowering the barrier to entry for new ransomware actors.
The Gunra ransomware actors employ a classic double-extortion model. Before encrypting victim data, they exfiltrate sensitive information and then threaten to publish this data on a dedicated leak site (DLS) hosted on the Tor network if the ransom is not paid. This tactic aims to increase pressure on victims to comply with the demands. The ransomware operators also utilize a customized, Tor-based negotiation portal for ransom discussions, further obscuring their identity and operations.
Victims of Gunra ransomware span a wide array of sectors across multiple continents, including the Americas, Europe, the Middle East, Africa, and the Asia-Pacific. Affected industries include healthcare and public health, financial services, critical manufacturing, transportation, government services, utilities, academia, media, retail, and professional services. The advisory notes that the FBI first observed Gunra ransomware in April 2025, and the group has adopted new branding aliases, such as "Golden Community," to support its expansion.
Gunra has also actively sought to expand its initial access capabilities by recruiting penetration testers and ethical hackers. These individuals are offered a share of the ransom profits in exchange for providing enterprise network access, effectively acting as initial access brokers. This strategy allows the core Gunra operators to focus on developing and managing their RaaS platform while affiliates and brokers handle the initial compromise and deployment.
The advisory provides detailed technical information on Gunra's tactics, techniques, and procedures (TTPs), mapped to the MITRE ATT&CK framework. It also offers crucial detection and mitigation guidance for organizations to defend against this evolving threat. Key recommendations include prioritizing the patching of known exploited vulnerabilities in internet-facing systems, such as VPN gateways and RDP-exposed infrastructure.
Furthermore, CISA strongly advises implementing and regularly testing offline, immutable backups. These backups should be stored in a physically separate, segmented location to ensure data recoverability without the need to pay a ransom. Network segmentation is also highlighted as a critical defense measure to restrict lateral movement from an initially compromised device to other systems within an organization's network.
Indicators of Compromise (IOCs) for Gunra ransomware are available for download in STIX XML and JSON formats, enabling security teams to enhance their detection capabilities. This joint advisory is part of the ongoing #StopRansomware initiative, aimed at providing network defenders with timely information and resources to combat ransomware threats effectively.
This new report details specific technical methods employed by the Gunra ransomware group, including the exploitation of Fortinet VPN flaws CVE-2024-55591 and CVE-2025-24472 to bypass multi-factor authentication by modifying authentication files. The article also highlights the group's use of Impacket tools for lateral movement and exfiltration via OneDrive, SharePoint, and Mega, along with their ChaCha20 and RSA-4096 encryption methods.
The FBI and South Korean government have issued a joint warning detailing the Gunra ransomware gang's exploitation of specific firewall vulnerabilities, CVE-2024-55591 and CVE-2025-24472, to target critical infrastructure sectors globally, including healthcare and financial services. This new advisory also highlights Gunra's shift to a ransomware-as-a-service model and the use of new aliases like 'Golden Community' to recruit initial access brokers, alongside the development of a Linux variant.
This advisory expands on previous reporting by detailing Gunra's operational model, which includes recruiting ethical hackers and penetration testers as initial access brokers. It also highlights the group's use of tools linked to North Korean government-backed actors and its influence from the Conti ransomware code. The FBI has been tracking Gunra since April of the previous year, noting its expansion into a formal ransomware-as-a-service affiliate by January of this year, operating under aliases like Golden Community.
This new reporting details the specific technical mechanisms Gunra ransomware employs for initial access and lateral movement, including the exploitation of CVE-2024-5559 in Schneider Electric PowerLogic P5 and CVE-2025-24472 in Fortinet products. It also elaborates on the ransomware's double extortion tactics, its RaaS affiliate program launched in January 2026, and observed post-exploitation activities such as credential dumping and log deletion.
This joint alert from U.S. and South Korean agencies specifically highlights the exploitation of two vulnerabilities in Fortinet products, for which patches were released in early 2025. The Gunra group is actively targeting these unpatched devices, including FortiOS and FortiProxy, to gain initial access and deploy ransomware against critical infrastructure and other sectors globally.
The Gunra ransomware gang is actively exploiting known vulnerabilities in Fortinet firewalls and VPN appliances, leveraging leaked Conti source code to bypass multi-factor authentication (MFA). This new reporting indicates that the group is specifically targeting critical infrastructure, a detail not previously emphasized in advisories focused on Gunra's broader operations.
This new reporting details how the Gunra ransomware group is specifically exploiting two legacy Fortinet vulnerabilities, CVE-2024-55591 and CVE-2025-24472, to gain initial access and super-admin privileges. The article also highlights the group's sophisticated methods for establishing persistence, bypassing multi-factor authentication, and exfiltrating data stealthily, often during off-hours, to maximize their double-extortion strategy.
This new reporting details the specific tactics and techniques Gunra affiliates employ after gaining initial access through Fortinet vulnerabilities. The article highlights the group's preference for using stolen sessions and legitimate tools like RDP to pivot into Active Directory and IT workstations, emphasizing their ability to modify configurations for persistence and undermine multi-factor authentication. Furthermore, it provides a more granular look at their data exfiltration methods, including the use of OneDrive and SharePoint, and the specific extensions and ransom notes left behind after encryption.
This SentinelOne report provides further details on the Gunra ransomware campaign, highlighting its expansion to Linux environments and the introduction of a formal Ransomware-as-a-Service (RaaS) affiliate program named "Golden Community." It also notes that a cryptographic flaw in the Linux variant of Gunra's malware allows for data recovery, a crucial detail not present in the initial CISA advisory.