VYPR
advisoryPublished Aug 10, 2026· 4 sources

#StopRansomware: CISA Details Gunra Ransomware Operations

CISA and international partners have issued a joint advisory detailing the Gunra ransomware, a RaaS variant that emerged in 2025 and expanded its operations in 2026, targeting critical infrastructure and government organizations.

A new joint Cybersecurity Advisory from CISA and international partners highlights the growing threat posed by the Gunra ransomware, a sophisticated variant that has evolved into a ransomware-as-a-service (RaaS) operation. First observed in April 2025, Gunra rapidly expanded its reach by early 2026, establishing a structured RaaS affiliate program advertised on dark web forums. This program provides financially motivated cybercriminals with access to a management panel, a configurable ransomware builder, and cross-platform payloads, significantly lowering the barrier to entry for new ransomware actors.

The Gunra ransomware actors employ a classic double-extortion model. Before encrypting victim data, they exfiltrate sensitive information and then threaten to publish this data on a dedicated leak site (DLS) hosted on the Tor network if the ransom is not paid. This tactic aims to increase pressure on victims to comply with the demands. The ransomware operators also utilize a customized, Tor-based negotiation portal for ransom discussions, further obscuring their identity and operations.

Victims of Gunra ransomware span a wide array of sectors across multiple continents, including the Americas, Europe, the Middle East, Africa, and the Asia-Pacific. Affected industries include healthcare and public health, financial services, critical manufacturing, transportation, government services, utilities, academia, media, retail, and professional services. The advisory notes that the FBI first observed Gunra ransomware in April 2025, and the group has adopted new branding aliases, such as "Golden Community," to support its expansion.

Gunra has also actively sought to expand its initial access capabilities by recruiting penetration testers and ethical hackers. These individuals are offered a share of the ransom profits in exchange for providing enterprise network access, effectively acting as initial access brokers. This strategy allows the core Gunra operators to focus on developing and managing their RaaS platform while affiliates and brokers handle the initial compromise and deployment.

The advisory provides detailed technical information on Gunra's tactics, techniques, and procedures (TTPs), mapped to the MITRE ATT&CK framework. It also offers crucial detection and mitigation guidance for organizations to defend against this evolving threat. Key recommendations include prioritizing the patching of known exploited vulnerabilities in internet-facing systems, such as VPN gateways and RDP-exposed infrastructure.

Furthermore, CISA strongly advises implementing and regularly testing offline, immutable backups. These backups should be stored in a physically separate, segmented location to ensure data recoverability without the need to pay a ransom. Network segmentation is also highlighted as a critical defense measure to restrict lateral movement from an initially compromised device to other systems within an organization's network.

Indicators of Compromise (IOCs) for Gunra ransomware are available for download in STIX XML and JSON formats, enabling security teams to enhance their detection capabilities. This joint advisory is part of the ongoing #StopRansomware initiative, aimed at providing network defenders with timely information and resources to combat ransomware threats effectively.

This new report details specific technical methods employed by the Gunra ransomware group, including the exploitation of Fortinet VPN flaws CVE-2024-55591 and CVE-2025-24472 to bypass multi-factor authentication by modifying authentication files. The article also highlights the group's use of Impacket tools for lateral movement and exfiltration via OneDrive, SharePoint, and Mega, along with their ChaCha20 and RSA-4096 encryption methods.

The FBI and South Korean government have issued a joint warning detailing the Gunra ransomware gang's exploitation of specific firewall vulnerabilities, CVE-2024-55591 and CVE-2025-24472, to target critical infrastructure sectors globally, including healthcare and financial services. This new advisory also highlights Gunra's shift to a ransomware-as-a-service model and the use of new aliases like 'Golden Community' to recruit initial access brokers, alongside the development of a Linux variant.

This advisory expands on previous reporting by detailing Gunra's operational model, which includes recruiting ethical hackers and penetration testers as initial access brokers. It also highlights the group's use of tools linked to North Korean government-backed actors and its influence from the Conti ransomware code. The FBI has been tracking Gunra since April of the previous year, noting its expansion into a formal ransomware-as-a-service affiliate by January of this year, operating under aliases like Golden Community.

Synthesized by Vypr AI