IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIFlash Threat Intel Brief

Gunra Ransomware Campaign

Fortinet Exploitation, Credential Theft, Data Exfiltration, Windows/Linux Encryption, and Recovery Risk

Ransomware-as-a-serviceDouble extortionWindows and Linux
Published
Aug 11, 2026
Brief Version
v1.0
Updated
Aug 11, 2026
AI Monitor
Card Library review queue
Brief ID
PANDA-FTIB-GUNRA-2026-001
Template
Flash Threat Brief v2.0
  • Patch and investigate exposed Fortinet and remote-access infrastructure: Prioritize CVE-2024-55591 and CVE-2025-24472, remove unnecessary public administration, eliminate default credentials, enforce lockout and MFA, and hunt historical access. Patching closes a path; it does not prove the device or downstream environment is clean.1
  • Treat suspicious access as an identity and session incident: Gunra actors created the superuser forticloud-sync, stole NTDS hashes and enterprise credentials, hijacked VDI sessions, captured authentication traffic, and modified OTP processing to bypass MFA. Revoke sessions, rotate reachable credentials, validate accounts and authentication code, and scope every connected trust path.1
  • Hunt before encryption: Investigate late-night administration, Impacket, RDP/SMB movement, OpenSSH tunneling, AnyDesk or Google Remote Desktop, RClone/FileZilla/Mega transfer, archive creation, OneDrive/SharePoint access by main.exe, log clearing, and shadow-copy deletion.1
  • Protect recovery systems as production assets: Gunra has deleted backups and archives in both primary and disaster-recovery environments. Maintain offline immutable copies, test restoration, separate backup administration, and assume reachable backup credentials may be exposed.1
  • Use the IOC set with dates and context: The joint advisory publishes historical IPs/domains, hashes, filenames, actor accounts, qTox IDs, and a malicious Fortinet username. Investigate timing and corroborating behavior before blocking or attribution because infrastructure may be historical or reassigned.1
  • Attribution remains operation-level: The evidence supports a Gunra criminal RaaS operator and affiliates, including the Golden Community alias. It does not establish named individuals, exclusive former-Conti ownership, a government sponsor, or one actor behind every Gunra intrusion.1, 2, 3

Gunra is a financially motivated double-extortion ransomware ecosystem. The malware appeared in April 2025 and draws from leaked Conti source code. In January 2026, the operation formalized a RaaS affiliate program that offers a management panel, configurable builders, Windows and Linux lockers, and documentation to criminal affiliates. The operator has used the Golden Community alias and recruited penetration testers or access brokers for enterprise access.1, 2, 3

The new joint government advisory turns Gunra from a largely malware- and leak-site-centered story into a documented intrusion campaign. FBI observations include exploitation of FortiOS/FortiProxy authentication-bypass vulnerabilities CVE-2024-55591 and CVE-2025-24472. KNPA observations add credential exposure, weak SSH controls, default SSL-VPN credentials, missing lockout, and malicious modification of remote-access accounts.1

After entry, Gunra actors have created the forticloud-sync superuser, used Impacket over SMB, dumped NTDS hashes, reused hashes and Kerberos tickets, stolen VDI sessions, sniffed authentication traffic, and modified a VDI portal so an attacker-selected OTP bypassed MFA. This makes identity, session, authentication-code, and administrative-change review as important as malware scanning.1

The operation collects business documents, databases, PII, internal email, and system/network configuration data. FBI reporting describes main.exe targeting OneDrive and SharePoint and archives exfiltrated to Mega, in one case reaching tens of terabytes. Common dual-use utilities include 7-Zip, WinRAR, RClone, FileZilla, AnyDesk, Google Remote Desktop, Mimikatz, Impacket, Sliver, and OpenSSH; their presence requires context, not automatic malicious attribution.1

Gunra encrypts accessible data with ChaCha20 and RSA-4096 and supports Windows and Linux environments. Common artifacts include .ENCRT and .CRYPT extensions and the ransom note R3ADM3.txt. Actors have deleted volume shadow copies and destroyed backup/archive data in both primary and disaster-recovery environments, so recovery assurance must be independent of the production identity plane.1, 2

For U.S. SMBs and MSP-managed customers, the most important lesson is blast radius. An exposed firewall, VPN, administrator workstation, VDI portal, domain controller, Microsoft 365 tenant, NAS, or backup platform can become a bridge to many systems and customers. An insurer or executive should ask for proof of fixed versions, historical exposure review, identity and session containment, data-access scoping, and tested clean recovery—not a patch receipt alone.1

IntelliOS previously maintained a Gunra actor card sourced from public ransomware and malware research. No PANDA Gunra brief or dedicated Gunra campaign card was published. This release creates both, updates the actor evidence with the new advisory, and keeps actor, malware, affiliate, campaign, IOC, and victim claims separated. It is a material delta rather than recycled coverage.1, 2, 3

Research and scoping note

Immediate priority: patch exposed edge devices, preserve and investigate historical access, invalidate stolen trust, protect and test recovery, and use the published IOC set to corroborate—not replace—behavioral investigation.1

Date / Period
Apr. 2025
Event / Meaning
FBI first observes Gunra; early research identifies a Conti-derived double-extortion encryptor and DLS.1, 2
Sources
1, 2
Date / Period
Mid-2025
Event / Meaning
Linux variant and broader cross-platform targeting become public; .ENCRT and .CRYPT artifacts are documented.1, 2
Sources
1, 2
Date / Period
Jan. 2026
Event / Meaning
Gunra launches a formal affiliate program with builders, management tooling, cross-platform lockers, and documentation; Golden Community branding is observed.1, 3
Sources
1, 3
Date / Period
Mar. 2026
Event / Meaning
S2W reports 32 confirmed damaged organizations in its measured set while cautioning that the sample does not define the full population.3
Sources
3
Date / Period
Aug. 10, 2026
Event / Meaning
U.S. and Republic of Korea agencies publish AA26-222A with observed intrusion chains, mitigations, STIX, and IOCs.1
Sources
1
Date / Period
Aug. 11, 2026
Event / Meaning
IntelliOS reconciles the new delta into a PANDA brief, a Gunra campaign card, and the existing Gunra actor record.1, 2, 3
Sources
1, 2, 3
Phase
1 — Preserve
Action
Capture firewall/VPN configuration, accounts, scheduled tasks, authentication and admin logs, VDI/RDP/SSH/SMB telemetry, cloud audit, EDR, memory, network flows, backup logs, and suspicious files before destructive cleanup when safe.1
Sources
1
Phase
2 — Contain
Action
Remove public management exposure, isolate suspected systems, disable malicious or unexplained accounts, revoke active sessions/tokens, block confirmed infrastructure after validation, and segment critical systems and backups.1
Sources
1
Phase
3 — Eradicate
Action
Patch affected Fortinet branches, remove unauthorized account/authentication changes and tunnels, rotate reachable secrets, rebuild systems whose integrity cannot be established, and validate domain/VDI/cloud trust.1
Sources
1
Phase
4 — Recover
Action
Restore from verified offline immutable backups, test database/NAS/application integrity, stage reconnection, monitor for re-entry, and preserve evidence needed for legal, insurer, and notification decisions.1
Sources
1
Phase
5 — Scope downstream
Action
MSPs and service providers should separately document each customer tenant, identity, remote path, affected asset, data exposure, notification decision, and closure evidence.1
Sources
1

This public brief retains defensible detection and scoping observables, not raw attacker infrastructure or operational instructions. Validate against owned telemetry before blocking or attributing.

Observable
Attacker IP address
Defender Use
23.239.119[.]2–6; 86.54.28[.]216; 103.125.234[.]14; 70.36.99[.]82; 211.21.210[.]181; 123.184.143[.]105; 182.204.21[.]240; 182.204.16[.]112; 123.244.187[.]144; 182.204.39[.]118; 67.43.53[.]10; 123.246.37[.]108; 91.201.66[.]146. CISA warns these are historical and must be vetted before blocking.1
Sources
1
Observable
Attacker domain / FQDN
Defender Use
datapub[.]news plus the three defanged onion addresses in AA26-222A/STIX. Use for historical investigation; do not browse actor infrastructure from production systems.1
Sources
1
Observable
SHA-256 — main.exe
Defender Use
2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751 and 834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1; tools used to exfiltrate OneDrive/SharePoint.1
Sources
1
Observable
SHA-256 — encryptors
Defender Use
91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0 (cryptor.exe); a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9 (msmp.exe).1
Sources
1
Observable
Malware filename / file name
Defender Use
main.exe, cryptor.exe, msmp.exe, R3ADM3.txt, .ENCRT, and .CRYPT. Confirm path, signer, hash, creation time, parent process, and adjacent activity.1, 2
Sources
1, 2
Observable
Malicious account
Defender Use
forticloud-sync — a superuser account created on vulnerable Fortinet devices through the documented exploit path.1
Sources
1
Observable
Behavioral pivots
Defender Use
Late-night 22:00–06:00 activity, log/history clearing, Impacket, NTDS dumping, RDP/SMB movement, SSH tunnels, archive creation, Mega/FileZilla/RClone transfer, OneDrive/SharePoint collection, WMI shadow-copy deletion, and backup destruction.1
Sources
1
Observable
Attacker-controlled URL / malicious URL
Defender Use
Tor negotiation/DLS URLs and qTox contacts are published in AA26-222A and its STIX package. Preserve from evidence; do not connect from production or personal systems.1
Sources
1
Observable
Negotiation emails
Defender Use
AA26-222A lists four defanged Proton/Gmail addresses associated with ransom negotiation. Treat as historical identifiers and preserve headers/context.1
Sources
1
Observable
qTox identifiers
Defender Use
Four long qTox IDs are published by the joint advisory. Match exact values from the STIX/advisory; do not manually contact them.1
Sources
1
Observable
Dual-use tool cluster
Defender Use
FileZilla, Amass, RClone, Sliver, 7-Zip, WinRAR, DBeaver, Slack, VS Code, MobaXterm, AnyDesk, Google Remote Desktop, Mimikatz, and Impacket require timing, user, process, destination, and change correlation.1
Sources
1
#
1
Tier
Tier 0 - Most Trusted
Publisher
CISA / FBI / DC3 / NSA / USSS / KNPA
Published
Aug. 10, 2026
Why Used
Controlling source for observed campaign mechanics, CVEs, IOCs, mitigations, sectors, and attribution language.
#
2
Tier
Tier 2 - High-Value Research
Publisher
AhnLab Security Intelligence Center
Published
July 23, 2025
Why Used
Primary malware research for April emergence, Conti-code similarity, encryption, ransom workflow, and early artifacts.
#
3
Tier
Tier 2 - High-Value Research
Publisher
S2W
Published
May 13, 2026
Why Used
RaaS evolution, dark-web recruitment, operational measurement, and sampling boundaries.
#
4
Tier
Tier 1 - Authoritative
Publisher
Microsoft
Published
June 8, 2025
Why Used
Vendor detection corroboration; not used to expand campaign scope.
#
5
Tier
Tier 0 - Most Trusted
Publisher
MITRE ATT&CK
Published
Version 19.1; checked Aug. 11, 2026
Why Used
Taxonomy for observed behaviors mapped by the joint advisory.
#
6
Tier
Tier 0 - Most Trusted
Publisher
CVE Program
Published
Checked Aug. 11, 2026
Why Used
Canonical vulnerability identifiers and affected-product references; campaign use remains controlled by the joint advisory.
#
7
Tier
Tier 1 - Authoritative
Publisher
Fortinet PSIRT
Published
Checked Aug. 11, 2026
Why Used
Vendor remediation context for the government-observed initial-access vulnerabilities.
#
8
Tier
Tier 3 - Corroborating News
Publisher
NyxLab
Published
Feb. 2026
Why Used
Corroborating targeting and access-path awareness; not used to establish a controlling claim.
#
9
Tier
Tier 7 - Inner Discovery
Publisher
CISA
Published
Aug. 10, 2026
Why Used
Machine-readable indicator expansion directly linked by the controlling advisory.
#
10
Tier
Tier 8 - Expansion Research / AI Agent Delta
Publisher
AhnLab ASEC
Published
Oct. 22, 2025
Why Used
Expansion research supporting Linux behavior and cross-platform boundaries; subordinate to current government observations.