Operation identity
Agreement
Gunra is a criminal RaaS ecosystem using Conti-derived ransomware.
Boundary / disagreement
Code lineage does not prove Conti operator continuity or state sponsorship.
CARDS
Gunra affiliates exploit internet-facing edge and remote-access systems, abuse exposed or default credentials, steal sessions and enterprise identities, move through VDI/AD and remote services, exfiltrate cloud and on-premises data, destroy recovery paths, and deploy Windows or Linux encryptors. The operator supports affiliates with builders, management tooling, negotiation infrastructure, leak-site pressure, and cross-platform lockers.
Last updated Aug 11, 2026, 10:00 AM EDT
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Campaign Chronology
April 2025
FBI and early malware research observe a Conti-derived double-extortion ransomware operation.
Mid-2025
Linux capability and broader Windows/Linux targeting become public.
January 2026
Gunra advertises affiliate management, builders, documentation, and cross-platform lockers; Golden Community branding appears.
August 10, 2026
U.S. and Republic of Korea agencies publish observed intrusion mechanics, CVEs, IOCs, and mitigations.
Victimology
Joint-advisory victim set
Sector and regional scope only
Government reporting describes multiple affected sectors and regions but does not publish a complete named victim list.
Gunra DLS listings
Actor claims
Leak-site entries support extortion activity but require independent verification and may not represent successful or accurately scoped incidents.
“No publicly named victim” is a disclosure statement, not an assessment that the campaign caused no harm.
Cross-Source Assessment
Agreement
Gunra is a criminal RaaS ecosystem using Conti-derived ransomware.
Boundary / disagreement
Code lineage does not prove Conti operator continuity or state sponsorship.
Agreement
Government-observed access includes Fortinet exploitation and credential/remote-access weaknesses.
Boundary / disagreement
Not every Gunra affiliate or incident necessarily uses the same path.
Agreement
Gunra targets multiple regions and sectors.
Boundary / disagreement
DLS and researcher counts are incomplete, source-bounded, and not a verified global census.
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
Conti-derived code is technical lineage, not proof of operator continuity. Gunra is a RaaS ecosystem, so affiliates may use different entry paths and tools. DLS listings and researcher victim counts are source-bounded claims, not a verified global census. Historical infrastructure must be vetted before blocking.
Evidence Controls
IntelliOS
Citations