Skip to content
Cybersecurity

What Is Gunra Ransomware? FBI, CISA Warning (2026)

/ 9 min read / Malik Tanveer Dhool

Gunra is a Conti-derived ransomware-as-a-service operation flagged in the FBI/CISA joint advisory AA26-222A. How it breaks in, who it targets, and how to spot it.

← Back to Blog
Share X in

WarBrief Live | October 8, 2026 | Cybersecurity

What is Gunra ransomware? It is a fast-moving ransomware-as-a-service operation built from the leaked source code of the notorious Conti gang, and it has become serious enough that six government agencies issued a joint warning about it. On August 10, 2026, the FBI, CISA, the NSA, the US Secret Service, the Pentagon’s Cyber Crime Center (DC3), and South Korea’s National Police Agency published advisory AA26-222A, documenting how Gunra affiliates break into hospitals, utilities, transport networks, and government systems — mostly through unpatched firewalls and VPN appliances. This explainer breaks down how the operation works, who it targets, and what defenders should do right now.

Key Takeaways

  • Gunra emerged in April 2025 from leaked Conti ransomware code and became a formal ransomware-as-a-service business — sold to criminal affiliates under the alias “Golden Community” — in January 2026.
  • The joint advisory AA26-222A, signed by the FBI, CISA, NSA, Secret Service, DC3, and South Korea’s KNPA, names healthcare, finance, critical manufacturing, transportation, and utilities among the targeted sectors.
  • Affiliates get in through known, long-patched flaws in Fortinet appliances (CVE-2024-55591 and CVE-2025-24472), then plant a rogue super-user account called “forticloud-sync” — the telltale sign of a Gunra intrusion.
  • Victims face double extortion: data stolen first, systems encrypted second, with five to seven days to pay before stolen data is published on the group’s dark-web leak site.

What is Gunra ransomware?

Gunra is a double-extortion ransomware strain that first appeared in April 2025, according to the FBI. Its code descends from the Conti ransomware source code that leaked publicly in 2022 — the same lineage behind other major operations such as Black Basta and Rhysida, according to threat researchers at Cyble. It runs on both Windows and Linux, with a Linux variant surfacing in mid-2025.

The operation’s real inflection point came in January 2026, when Gunra’s operators opened a formal ransomware-as-a-service (RaaS) affiliate program advertised on dark-web forums under the alias “Golden Community.” Affiliates buy a complete package: a management panel, a configurable ransomware builder, cross-platform encryptor payloads, and written documentation, according to Picus Security’s technical analysis. The program even recruits penetration testers and ethical hackers as initial-access brokers, paying them a share of the ransom. Advisory reporting indicates affiliates keep roughly 80 percent of each ransom while the operators take 20 percent — a generous split that has fueled rapid expansion.

Like the KillSec operation broken down in our earlier explainer, Gunra follows the modern RaaS franchise model: the core developers supply the malware and infrastructure, while a rotating cast of affiliates supplies the victims. That model is exactly why ransomware keeps scaling even after high-profile takedowns — removing one affiliate changes nothing for the operators.

How does Gunra ransomware break in?

Gunra’s entry route is embarrassingly ordinary. Affiliates exploit two known authentication-bypass vulnerabilities in Fortinet’s FortiOS and FortiProxy products: CVE-2024-55591 (CVSS 9.6, critical — super-admin access via Node.js websocket requests) and CVE-2025-24472 (CVSS 8.1, high — super-admin access via crafted proxy requests). Fortinet released patches for both flaws long ago; the devices being breached today are the unpatched remainder, as OpenVPN’s analysis of the advisory notes. Exposed or default credentials on VPN gateways and SSH access-control weaknesses provide backup routes in.

Once inside, the intruders move fast. They create a rogue Fortinet super-user account named “forticloud-sync” with a hard-coded password, installed via a scheduled task — that account name is the single clearest indicator of a Gunra compromise on a firewall, and defenders are advised to hunt for it immediately. In at least one case investigated by South Korean police, the attackers went further: they modified the authentication files of a virtual-desktop portal so that one attacker-chosen one-time password would always be accepted — a back door inside the multi-factor authentication mechanism itself, as detailed by Hard2Bit’s breakdown of the advisory.

The attack sequence then follows the standard double-extortion playbook, executed at speed. Affiliates first steal data — documents, databases, personally identifiable information, internal email — exfiltrating it through cloud services including OneDrive and SharePoint. They delete Volume Shadow Copies and destroy backups to block recovery. Only then do they detonate the encryptor: a multithreaded payload combining ChaCha20 symmetric encryption with RSA-4096 asymmetric keys, renaming files with the .ENCRT extension (older samples used .CRYPT; the Linux variant uses .GNRA) and dropping a ransom note named R3ADM3.txt in every folder. Victims are pushed to a Tor-based negotiation portal and given five to seven days before stolen data is published on the group’s dedicated leak site.

Incident-response researchers tracking the campaign note that Gunra affiliates have listed more than 30 victims publicly on their dark-web leak site as of early October 2026, with individual ransom demands reported in the $7 million to $10 million range — figures drawn from secondary trackers that shift over time and should be treated as indicative rather than exact.

What is Gunra ransomware - breached firewall appliance illustration
AI-generated illustration

Background and timeline

  • 2022: The Conti ransomware group’s source code leaks publicly, spawning a generation of derivative operations.
  • April 2025: The FBI first observes Gunra in the wild, hitting Windows environments.
  • Mid-2025: A Linux variant of Gunra surfaces, expanding the operation’s reach to enterprise server infrastructure.
  • January 2026: Gunra’s operators launch the formal “Golden Community” affiliate program on dark-web forums, with a management panel, configurable builder, and cross-platform payloads.
  • August 10, 2026: The FBI, CISA, NSA, US Secret Service, DoD Cyber Crime Center (DC3), and South Korea’s National Police Agency publish joint #StopRansomware advisory AA26-222A, with technical indicators, a MITRE ATT&CK mapping, and downloadable STIX indicators.
  • October 7, 2026: Independent tracking puts the group’s public victim count above 30 organizations across multiple continents.

By the numbers

Metric Figure Source
First observed April 2025 FBI (via CISA AA26-222A) — CONFIRMED
Code lineage Leaked Conti source code (2022) Cyble, Picus Security — CONFIRMED
RaaS program launched January 2026 (“Golden Community”) Advisory reporting (Cyble, Picus) — CONFIRMED
Joint advisory AA26-222A, August 10, 2026 CISA — CONFIRMED
Signing agencies FBI, CISA, NSA, USSS, DC3, ROK KNPA CISA — CONFIRMED
Initial-access CVEs CVE-2024-55591 (CVSS 9.6), CVE-2025-24472 (CVSS 8.1) CISA AA26-222A — CONFIRMED
Encryption scheme ChaCha20 + RSA-4096 Picus, Cyble — CONFIRMED
Extortion window 5–7 days Cyble, QUE.com, Any.RUN — CONFIRMED
Rogue firewall account “forticloud-sync” super-user Incident-response reporting — CONFIRMED
Affiliate revenue split ~80% to affiliates / 20% to operators Advisory reporting — REPORTED
Public leak-site victims 30+ (one August count: 51) Secondary trackers — REPORTED
Reported ransom demands $7M–$10M Any.RUN — REPORTED

Figures marked REPORTED come from secondary trackers and vary between sources and over time; figures marked CONFIRMED are corroborated by the joint government advisory or multiple independent analyses.

What this means for US/UK/EU readers

Gunra is a business problem that becomes a public problem. The sectors named in the advisory — hospitals, financial services, manufacturers, transport and logistics firms, utilities — are the services ordinary life runs on. When a hospital’s IT systems go down to ransomware, appointments are cancelled and records become inaccessible; when a water utility or a logistics firm is hit, bills, deliveries, and schedules slip. Gunra’s affiliates have hit victims across the Americas, Europe, the Middle East, Africa, and Asia-Pacific, so no region is exempt.

The wartime context raises the stakes further. Gunra explicitly targets government and critical-infrastructure organizations, and the advisory’s publication by six agencies — including South Korea’s police, reflecting real incidents investigated there — shows the campaign is genuinely international. Ransomware crews are financially motivated, not ideological, but the infrastructure they cripple is the same infrastructure a conflict would strain first.

For organizations, the advisory’s guidance is blunt and cheap relative to a ransom: patch internet-facing VPN gateways and firewalls immediately (the FortiOS flaws Gunra uses have had fixes for over a year), keep tested offline and immutable backups in a separate network segment, segment networks to slow lateral movement, and hunt for the “forticloud-sync” account on Fortinet appliances. One unusual silver lining: for the Linux variant’s .GNRA files, researchers found the encryption keys are generated with a weak random-number generator seeded from the system clock — meaning keys may be reconstructable from file timestamps, so victims should preserve encrypted files and their timestamps before touching anything. There is no equivalent recovery path documented for Windows.

What is Gunra ransomware - hospital and power plant under cyber threat illustration
AI-generated illustration

Different perspectives

Security vendors and the agencies behind the advisory frame Gunra as a patching and backup failure rather than an exotic new threat — the group gets in through vulnerabilities that have had fixes for over a year, and the advisory’s lead recommendation is prioritized patching of internet-facing systems. Some analysts go further, arguing the real lesson is architectural: when a single vendor’s firewall is the only remote-access path, its compromise becomes a company-wide outage, and organizations need a second, independent break-glass access route.

From the attackers’ side, the 80/20 revenue split and the open recruitment of penetration testers show how professionalized the ransomware economy has become — affiliates are treated as valued partners, not disposable contractors. That business logic is precisely what makes the franchise model hard to kill: as our Warlock ransomware explainer showed with a different crew, taking down one brand’s infrastructure rarely dents the affiliate marketplace for long. The WarBrief intelligence hub tracks how these cyber campaigns intersect with the wider conflict landscape.

What to watch next

Three things will determine whether Gunra fades or becomes a top-tier brand. First, the affiliate count: the “Golden Community” program is still young, and law-enforcement attention — six agencies co-signing one advisory — sometimes pushes affiliates toward quieter operations and sometimes does nothing at all. Second, patching velocity: every unpatched FortiOS appliance on the internet is a standing invitation, and the defenders’ race is measured in months against an adversary’s hours. Third, the leak site: the public victim count is the most honest metric of the operation’s momentum, and a sudden jump would signal the affiliate program is scaling as designed. Defenders should also watch for the group’s response to the Linux key-recovery research — a fixed random-number generator in the next variant would close the one free recovery path victims currently have.

Frequently asked questions

How does Gunra ransomware gain initial access?
Mainly by exploiting known, already-patched vulnerabilities in internet-facing Fortinet devices — the FortiOS/FortiProxy authentication bypasses CVE-2024-55591 and CVE-2025-24472 — plus exposed or default credentials on VPN gateways and SSH weaknesses. No zero-day has been documented: it gets in through what administrators left unpatched.

Who signed advisory AA26-222A and why does it matter?
The FBI, CISA, the NSA, the US Secret Service, the DoD Cyber Crime Center (DC3), and South Korea’s National Police Agency. It matters because the advisory combines forensic data from real incidents in two countries, ships downloadable STIX indicators and a full MITRE ATT&CK mapping, and confirms the group operates globally across critical-infrastructure sectors.

Can files encrypted by Gunra be recovered without paying?
For the Linux variant (files ending in .GNRA), possibly yes: its encryption keys are generated with a weak random-number generator seeded from the system clock and may be reconstructable from file timestamps, according to research cited in the advisory itself. No equivalent weakness is documented for the Windows variant. Either way, preserve encrypted files, their timestamps, and the ransom notes before touching anything, and do not pay — that is the FBI and CISA’s standing guidance.

How did Gunra bypass multi-factor authentication?
In at least one case investigated by South Korean police, the attackers modified the authentication files of a virtual-desktop portal so that one attacker-chosen one-time password would always be accepted. MFA stayed active for everyone else — the back door sat inside the validation mechanism itself, not in the MFA protocol.

What should organizations do right now?
Patch internet-facing VPN and firewall appliances immediately, with the two Fortinet flaws at the top of the list; keep tested offline, immutable backups in a physically separate network segment; segment networks to restrict lateral movement; and hunt Fortinet appliances for the rogue “forticloud-sync” super-user account, which is the clearest known indicator of a Gunra intrusion.

Sources

Written by

Malik Tanveer Dhool

Defense and intelligence analysis for WarBrief.live. Covering conflict, technology, and geopolitical strategy.

Discussion 0

Share analysis, corrections, or context. Be civil — comments are moderated.

Join the discussion

Your comment will appear after moderation. Please keep it civil and on-topic.