Gunra Ransomware Campaign
Fortinet Exploitation, Credential Theft, Data Exfiltration, Windows/Linux Encryption, and Recovery Risk
- Field
- User Topic
- Value
- Gunra ransomware and the campaign behind its edge-device exploitation, credential theft, data exfiltration, and cross-platform extortion.
- Field
- Interpreted Questions
- Value
- What is Gunra, what changed in the joint government advisory, how does it gain and expand access, what can defenders hunt, and what should U.S. SMBs, MSPs, insurers, and incident teams do now? Which claims describe the malware, the RaaS operator, affiliates, victims, or merely historical infrastructure?
- Field
- Initial Observations
- Value
- Gunra first emerged in April 2025 as Conti-derived double-extortion ransomware and formalized a RaaS affiliate program in January 2026. The Aug. 10 joint advisory materially advances the public record with FBI- and KNPA-observed exploitation of internet-facing Fortinet and VPN infrastructure, credential and session theft, MFA bypass, OneDrive/SharePoint exfiltration, Windows/Linux encryption, backup destruction, and a substantial IOC set. This is a new PANDA campaign product, not a duplicate of the pre-existing Gunra actor card; that actor card is being reconciled to the same evidence.1, 2, 3
- Field
- Source Coverage
- Value
- Tier
- Tier 0 - Most Trusted
- Checked
- 4
- Candidate Hits
- 4
- Planner Selected
- 3
- Not Used
- 1
- Tier
- Tier 1 - Authoritative
- Checked
- 6
- Candidate Hits
- 5
- Planner Selected
- 3
- Not Used
- 3
- Tier
- Tier 2 - High-Value Research
- Checked
- 8
- Candidate Hits
- 7
- Planner Selected
- 3
- Not Used
- 5
- Tier
- Tier 3 - Corroborating News
- Checked
- 5
- Candidate Hits
- 4
- Planner Selected
- 0
- Not Used
- 5
- Tier
- Tier 4 - Community Signal
- Checked
- 3
- Candidate Hits
- 2
- Planner Selected
- 0
- Not Used
- 3
- Tier
- Tier 5 - Custom Source
- Checked
- 1
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 1
- Tier
- Tier 6 - Custom Integrations with API/Keys
- Checked
- 1
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 1
- Tier
- Tier 7 - Inner Discovery
- Checked
- 3
- Candidate Hits
- 3
- Planner Selected
- 2
- Not Used
- 1
- Tier
- Tier 8 - Expansion Research / AI Agent Delta
- Checked
- 3
- Candidate Hits
- 3
- Planner Selected
- 2
- Not Used
- 1
- Tier
- Total
- Checked
- 34
- Candidate Hits
- 28
- Planner Selected
- 13
- Not Used
- 21
Tier Checked Candidate Hits Planner Selected Not Used Tier 0 - Most Trusted 4 4 3 1 Tier 1 - Authoritative 6 5 3 3 Tier 2 - High-Value Research 8 7 3 5 Tier 3 - Corroborating News 5 4 0 5 Tier 4 - Community Signal 3 2 0 3 Tier 5 - Custom Source 1 0 0 1 Tier 6 - Custom Integrations with API/Keys 1 0 0 1 Tier 7 - Inner Discovery 3 3 2 1 Tier 8 - Expansion Research / AI Agent Delta 3 3 2 1 Total 34 28 13 21
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | Gunra ransomware and the campaign behind its edge-device exploitation, credential theft, data exfiltration, and cross-platform extortion. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | What is Gunra, what changed in the joint government advisory, how does it gain and expand access, what can defenders hunt, and what should U.S. SMBs, MSPs, insurers, and incident teams do now? Which claims describe the malware, the RaaS operator, affiliates, victims, or merely historical infrastructure? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | Gunra first emerged in April 2025 as Conti-derived double-extortion ransomware and formalized a RaaS affiliate program in January 2026. The Aug. 10 joint advisory materially advances the public record with FBI- and KNPA-observed exploitation of internet-facing Fortinet and VPN infrastructure, credential and session theft, MFA bypass, OneDrive/SharePoint exfiltration, Windows/Linux encryption, backup destruction, and a substantial IOC set. This is a new PANDA campaign product, not a duplicate of the pre-existing Gunra actor card; that actor card is being reconciled to the same evidence.1, 2, 3 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
|
Gunra is not merely an encryptor: the documented campaign spans edge exploitation, identity compromise, cloud collection, lateral movement, backup destruction, and cross-platform impact.1
First observed
Apr. 2025
FBI observation and early public malware research.
RaaS expansion
Jan. 2026
Formal affiliate program with cross-platform builders and management tooling.
Operating model
Double extortion
Data theft plus Windows/Linux encryption and leak/sale pressure.
Current trigger
Aug. 10, 2026
Joint government advisory with observed intrusions and downloadable IOCs.
- Dimension
- Operation
- Current Assessment
- Gunra / Golden Community RaaS
- Operational Meaning
- Operator plus affiliates; do not assume one universal intrusion team.1
- Dimension
- Observed access
- Current Assessment
- Fortinet CVEs and remote-access credential/control weakness
- Operational Meaning
- Patch, harden, and investigate historical entry rather than treating this as malware-only.1
- Dimension
- Post-access reach
- Current Assessment
- VDI, AD, cloud storage, databases, NAS, backups
- Operational Meaning
- Scope privileged trust and downstream systems before declaring containment.1
- Dimension
- Platforms
- Current Assessment
- Windows and Linux
- Dimension
- Impact
- Current Assessment
- Data theft, encryption, leak/sale pressure, recovery destruction
- Operational Meaning
- Prepare breach response and business recovery in parallel.1
- Dimension
- Confidence
- Current Assessment
- High for observed mechanics; bounded for identity/victimology
| Dimension | Current Assessment | Operational Meaning |
|---|---|---|
| Operation | Gunra / Golden Community RaaS | Operator plus affiliates; do not assume one universal intrusion team.1 |
| Observed access | Fortinet CVEs and remote-access credential/control weakness | Patch, harden, and investigate historical entry rather than treating this as malware-only.1 |
| Post-access reach | VDI, AD, cloud storage, databases, NAS, backups | Scope privileged trust and downstream systems before declaring containment.1 |
| Platforms | Windows and Linux | Inventory servers and shared storage, not only user endpoints.1, 2 |
| Impact | Data theft, encryption, leak/sale pressure, recovery destruction | Prepare breach response and business recovery in parallel.1 |
| Confidence | High for observed mechanics; bounded for identity/victimology | Use Gunra operation attribution without naming people, states, or unverified victims.1, 3 |
Gunra is both a ransomware family and the service operated around it. It began in April 2025 with code derived from or influenced by leaked Conti source code, then expanded into a formal RaaS program in January 2026. Affiliates receive a management panel, configurable builder, cross-platform lockers, and operating documentation; the operator has also used the alias Golden Community.1, 2, 3
The strongest observed entry paths are exploitation of CVE-2024-55591 and CVE-2025-24472 in FortiOS/FortiProxy, credential exposure, weak SSH controls, default VPN credentials, and absent account lockout. Post-access activity includes malicious account creation, credential and session theft, VDI/RDP movement, MFA bypass, domain-controller dumping, cloud-data exfiltration, and destructive encryption.1
Conti-derived code does not prove that former Conti personnel operate Gunra. The Gunra label also does not identify a particular affiliate. This brief attributes the documented activity to Gunra actors as the joint advisory does, while leaving human identity, geography, and state sponsorship unassigned.1, 2
The same Gunra evidence produces different decisions by role; no audience should treat patch state alone as incident closure.
- Persona
- Executive / owner
- Primary Question
- Can this interrupt operations or expose customers?
- Decision / Evidence
- Require edge-remediation proof, incident scope, data/recovery impact, owner, and residual uncertainty.1
- Persona
- SOC / IR
- Primary Question
- Was access achieved before encryption?
- Decision / Evidence
- Correlate edge, identity, VDI, AD, cloud, endpoint, egress, and backup evidence with atomic IOCs.1
- Persona
- Network / identity owner
- Primary Question
- Which trust paths were reachable?
- Decision / Evidence
- Validate fixed versions, management exposure, accounts, sessions, MFA code, RDP/SMB/SSH, and privileged changes.1
- Persona
- MSP / service provider
- Primary Question
- Which customer tenants were reachable?
- Decision / Evidence
- Produce customer-specific access, identity, endpoint, data, notification, and closure records.1
- Persona
- Insurer / counsel
- Primary Question
- Is there a covered or reportable event?
- Decision / Evidence
- Separate vulnerability, IOC contact, access, data acquisition, encryption, recovery cost, and confirmed affected parties.1
- Persona
- Backup / recovery owner
- Primary Question
- Can restoration survive compromised production identity?
- Decision / Evidence
- Prove offline immutable copies, separate administration, tested restoration, and clean recovery sequencing.1
| Persona | Primary Question | Decision / Evidence |
|---|---|---|
| Executive / owner | Can this interrupt operations or expose customers? | Require edge-remediation proof, incident scope, data/recovery impact, owner, and residual uncertainty.1 |
| SOC / IR | Was access achieved before encryption? | Correlate edge, identity, VDI, AD, cloud, endpoint, egress, and backup evidence with atomic IOCs.1 |
| Network / identity owner | Which trust paths were reachable? | Validate fixed versions, management exposure, accounts, sessions, MFA code, RDP/SMB/SSH, and privileged changes.1 |
| MSP / service provider | Which customer tenants were reachable? | Produce customer-specific access, identity, endpoint, data, notification, and closure records.1 |
| Insurer / counsel | Is there a covered or reportable event? | Separate vulnerability, IOC contact, access, data acquisition, encryption, recovery cost, and confirmed affected parties.1 |
| Backup / recovery owner | Can restoration survive compromised production identity? | Prove offline immutable copies, separate administration, tested restoration, and clean recovery sequencing.1 |
- Patch and investigate exposed Fortinet and remote-access infrastructure: Prioritize CVE-2024-55591 and CVE-2025-24472, remove unnecessary public administration, eliminate default credentials, enforce lockout and MFA, and hunt historical access. Patching closes a path; it does not prove the device or downstream environment is clean.1
- Treat suspicious access as an identity and session incident: Gunra actors created the superuser forticloud-sync, stole NTDS hashes and enterprise credentials, hijacked VDI sessions, captured authentication traffic, and modified OTP processing to bypass MFA. Revoke sessions, rotate reachable credentials, validate accounts and authentication code, and scope every connected trust path.1
- Hunt before encryption: Investigate late-night administration, Impacket, RDP/SMB movement, OpenSSH tunneling, AnyDesk or Google Remote Desktop, RClone/FileZilla/Mega transfer, archive creation, OneDrive/SharePoint access by main.exe, log clearing, and shadow-copy deletion.1
- Protect recovery systems as production assets: Gunra has deleted backups and archives in both primary and disaster-recovery environments. Maintain offline immutable copies, test restoration, separate backup administration, and assume reachable backup credentials may be exposed.1
- Use the IOC set with dates and context: The joint advisory publishes historical IPs/domains, hashes, filenames, actor accounts, qTox IDs, and a malicious Fortinet username. Investigate timing and corroborating behavior before blocking or attribution because infrastructure may be historical or reassigned.1
- Attribution remains operation-level: The evidence supports a Gunra criminal RaaS operator and affiliates, including the Golden Community alias. It does not establish named individuals, exclusive former-Conti ownership, a government sponsor, or one actor behind every Gunra intrusion.1, 2, 3
Gunra is a financially motivated double-extortion ransomware ecosystem. The malware appeared in April 2025 and draws from leaked Conti source code. In January 2026, the operation formalized a RaaS affiliate program that offers a management panel, configurable builders, Windows and Linux lockers, and documentation to criminal affiliates. The operator has used the Golden Community alias and recruited penetration testers or access brokers for enterprise access.1, 2, 3
The new joint government advisory turns Gunra from a largely malware- and leak-site-centered story into a documented intrusion campaign. FBI observations include exploitation of FortiOS/FortiProxy authentication-bypass vulnerabilities CVE-2024-55591 and CVE-2025-24472. KNPA observations add credential exposure, weak SSH controls, default SSL-VPN credentials, missing lockout, and malicious modification of remote-access accounts.1
After entry, Gunra actors have created the forticloud-sync superuser, used Impacket over SMB, dumped NTDS hashes, reused hashes and Kerberos tickets, stolen VDI sessions, sniffed authentication traffic, and modified a VDI portal so an attacker-selected OTP bypassed MFA. This makes identity, session, authentication-code, and administrative-change review as important as malware scanning.1
The operation collects business documents, databases, PII, internal email, and system/network configuration data. FBI reporting describes main.exe targeting OneDrive and SharePoint and archives exfiltrated to Mega, in one case reaching tens of terabytes. Common dual-use utilities include 7-Zip, WinRAR, RClone, FileZilla, AnyDesk, Google Remote Desktop, Mimikatz, Impacket, Sliver, and OpenSSH; their presence requires context, not automatic malicious attribution.1
Gunra encrypts accessible data with ChaCha20 and RSA-4096 and supports Windows and Linux environments. Common artifacts include .ENCRT and .CRYPT extensions and the ransom note R3ADM3.txt. Actors have deleted volume shadow copies and destroyed backup/archive data in both primary and disaster-recovery environments, so recovery assurance must be independent of the production identity plane.1, 2
For U.S. SMBs and MSP-managed customers, the most important lesson is blast radius. An exposed firewall, VPN, administrator workstation, VDI portal, domain controller, Microsoft 365 tenant, NAS, or backup platform can become a bridge to many systems and customers. An insurer or executive should ask for proof of fixed versions, historical exposure review, identity and session containment, data-access scoping, and tested clean recovery—not a patch receipt alone.1
IntelliOS previously maintained a Gunra actor card sourced from public ransomware and malware research. No PANDA Gunra brief or dedicated Gunra campaign card was published. This release creates both, updates the actor evidence with the new advisory, and keeps actor, malware, affiliate, campaign, IOC, and victim claims separated. It is a material delta rather than recycled coverage.1, 2, 3
Research and scoping note
Immediate priority: patch exposed edge devices, preserve and investigate historical access, invalidate stolen trust, protect and test recovery, and use the published IOC set to corroborate—not replace—behavioral investigation.1
- Risk
- Internet edge
- Why It Matters
- A firewall or VPN compromise can bypass the normal perimeter and expose privileged administration.
- Proof / Action
- Historical reachability, fixed build, config/account review, and retained logs.1
- Risk
- Identity persistence
- Why It Matters
- Stolen sessions, hashes, tickets, and modified OTP logic can survive endpoint cleanup.
- Proof / Action
- Session revocation, credential rotation, account/config diff, and authentication-code validation.1
- Risk
- Cloud and server data
- Why It Matters
- OneDrive, SharePoint, databases, PII, email, and network configuration may be stolen before encryption.
- Proof / Action
- Cloud audit, query/download history, archive and egress evidence, and data-owner scoping.1
- Risk
- Recovery destruction
- Why It Matters
- Primary and disaster-recovery backups may be deliberately deleted.
- Proof / Action
- Independent backup identities, immutable/offline copies, integrity checks, and restoration tests.1
- Risk
- MSP/downstream reach
- Why It Matters
- Shared administration can create multi-customer blast radius.
- Proof / Action
- Per-tenant access and impact evidence rather than portfolio-wide assumptions.1
| Risk | Why It Matters | Proof / Action |
|---|---|---|
| Internet edge | A firewall or VPN compromise can bypass the normal perimeter and expose privileged administration. | Historical reachability, fixed build, config/account review, and retained logs.1 |
| Identity persistence | Stolen sessions, hashes, tickets, and modified OTP logic can survive endpoint cleanup. | Session revocation, credential rotation, account/config diff, and authentication-code validation.1 |
| Cloud and server data | OneDrive, SharePoint, databases, PII, email, and network configuration may be stolen before encryption. | Cloud audit, query/download history, archive and egress evidence, and data-owner scoping.1 |
| Recovery destruction | Primary and disaster-recovery backups may be deliberately deleted. | Independent backup identities, immutable/offline copies, integrity checks, and restoration tests.1 |
| MSP/downstream reach | Shared administration can create multi-customer blast radius. | Per-tenant access and impact evidence rather than portfolio-wide assumptions.1 |
- Date / Period
- Apr. 2025
- Date / Period
- Mid-2025
- Date / Period
- Jan. 2026
- Date / Period
- Mar. 2026
- Event / Meaning
- S2W reports 32 confirmed damaged organizations in its measured set while cautioning that the sample does not define the full population.3
- Sources
- 3
| Date / Period | Event / Meaning | Sources |
|---|---|---|
| Apr. 2025 | FBI first observes Gunra; early research identifies a Conti-derived double-extortion encryptor and DLS.1, 2 | 1, 2 |
| Mid-2025 | Linux variant and broader cross-platform targeting become public; .ENCRT and .CRYPT artifacts are documented.1, 2 | 1, 2 |
| Jan. 2026 | Gunra launches a formal affiliate program with builders, management tooling, cross-platform lockers, and documentation; Golden Community branding is observed.1, 3 | 1, 3 |
| Mar. 2026 | S2W reports 32 confirmed damaged organizations in its measured set while cautioning that the sample does not define the full population.3 | 3 |
| Aug. 10, 2026 | U.S. and Republic of Korea agencies publish AA26-222A with observed intrusion chains, mitigations, STIX, and IOCs.1 | 1 |
| Aug. 11, 2026 | IntelliOS reconciles the new delta into a PANDA brief, a Gunra campaign card, and the existing Gunra actor record.1, 2, 3 | 1, 2, 3 |
- Phase
- 1 — Preserve
- Action
- Capture firewall/VPN configuration, accounts, scheduled tasks, authentication and admin logs, VDI/RDP/SSH/SMB telemetry, cloud audit, EDR, memory, network flows, backup logs, and suspicious files before destructive cleanup when safe.1
- Sources
- 1
- Phase
- 2 — Contain
- Action
- Remove public management exposure, isolate suspected systems, disable malicious or unexplained accounts, revoke active sessions/tokens, block confirmed infrastructure after validation, and segment critical systems and backups.1
- Sources
- 1
- Phase
- 3 — Eradicate
- Action
- Patch affected Fortinet branches, remove unauthorized account/authentication changes and tunnels, rotate reachable secrets, rebuild systems whose integrity cannot be established, and validate domain/VDI/cloud trust.1
- Sources
- 1
| Phase | Action | Sources |
|---|---|---|
| 1 — Preserve | Capture firewall/VPN configuration, accounts, scheduled tasks, authentication and admin logs, VDI/RDP/SSH/SMB telemetry, cloud audit, EDR, memory, network flows, backup logs, and suspicious files before destructive cleanup when safe.1 | 1 |
| 2 — Contain | Remove public management exposure, isolate suspected systems, disable malicious or unexplained accounts, revoke active sessions/tokens, block confirmed infrastructure after validation, and segment critical systems and backups.1 | 1 |
| 3 — Eradicate | Patch affected Fortinet branches, remove unauthorized account/authentication changes and tunnels, rotate reachable secrets, rebuild systems whose integrity cannot be established, and validate domain/VDI/cloud trust.1 | 1 |
| 4 — Recover | Restore from verified offline immutable backups, test database/NAS/application integrity, stage reconnection, monitor for re-entry, and preserve evidence needed for legal, insurer, and notification decisions.1 | 1 |
| 5 — Scope downstream | MSPs and service providers should separately document each customer tenant, identity, remote path, affected asset, data exposure, notification decision, and closure evidence.1 | 1 |
- Term
- Ransomware-as-a-service
- Meaning Here
- An operator supplies ransomware and infrastructure to affiliates who conduct intrusions, usually sharing proceeds.1
- Sources
- 1
- Term
- Double extortion
- Meaning Here
- Stealing data before encryption and threatening publication or sale in addition to denying access.1
- Sources
- 1
- Term
- Dedicated leak site
- Meaning Here
- A Tor or clearnet site used to pressure victims and advertise stolen data; listings are actor claims, not independently verified victim findings.1
- Sources
- 1
- Term
- Conti-derived
| Term | Meaning Here | Sources |
|---|---|---|
| Ransomware-as-a-service | An operator supplies ransomware and infrastructure to affiliates who conduct intrusions, usually sharing proceeds.1 | 1 |
| Double extortion | Stealing data before encryption and threatening publication or sale in addition to denying access.1 | 1 |
| Dedicated leak site | A Tor or clearnet site used to pressure victims and advertise stolen data; listings are actor claims, not independently verified victim findings.1 | 1 |
| Conti-derived | Code resemblance or reuse from leaked Conti source; it does not establish operator identity.1, 2 | 1, 2 |
| Affiliate | A criminal customer/operator who uses the RaaS platform to conduct an intrusion; affiliates may use different access paths and tools.1, 3 | 1, 3 |
- Behavior / ATT&CK
- T1190 — Exploit Public-Facing Application
- Campaign Mapping
- Exploitation of internet-facing FortiOS/FortiProxy and VPN infrastructure, including CVE-2024-55591 and CVE-2025-24472.1
- Sources
- 1
- Behavior / ATT&CK
- T1078 — Valid Accounts
- Campaign Mapping
- Default, exposed, stolen, modified, and newly created accounts support entry and persistence.1
- Sources
- 1
- Behavior / ATT&CK
- T1003 — OS Credential Dumping
- Campaign Mapping
- secretsdump.py and access-control server compromise yielded password hashes and enterprise credentials.1
- Sources
- 1
- Behavior / ATT&CK
- T1021 — Remote Services
- Campaign Mapping
- RDP and SMB/Impacket support movement from edge/VDI access into AD and critical servers.1
- Sources
- 1
- Behavior / ATT&CK
- T1530 — Data from Cloud Storage
- Campaign Mapping
- main.exe targeted OneDrive and SharePoint data.1
- Sources
- 1
- Behavior / ATT&CK
- T1567 — Exfiltration Over Web Service
- Campaign Mapping
- Archived data was transferred to Mega; RClone and other tools are also documented.1
- Sources
- 1
- Behavior / ATT&CK
- T1486 — Data Encrypted for Impact
| Behavior / ATT&CK | Campaign Mapping | Sources |
|---|---|---|
| T1190 — Exploit Public-Facing Application | Exploitation of internet-facing FortiOS/FortiProxy and VPN infrastructure, including CVE-2024-55591 and CVE-2025-24472.1 | 1 |
| T1078 — Valid Accounts | Default, exposed, stolen, modified, and newly created accounts support entry and persistence.1 | 1 |
| T1003 — OS Credential Dumping | secretsdump.py and access-control server compromise yielded password hashes and enterprise credentials.1 | 1 |
| T1021 — Remote Services | RDP and SMB/Impacket support movement from edge/VDI access into AD and critical servers.1 | 1 |
| T1530 — Data from Cloud Storage | main.exe targeted OneDrive and SharePoint data.1 | 1 |
| T1567 — Exfiltration Over Web Service | Archived data was transferred to Mega; RClone and other tools are also documented.1 | 1 |
| T1486 — Data Encrypted for Impact | Windows/Linux lockers encrypt accessible files, databases, and NAS assets.1, 2 | 1, 2 |
| T1490 — Inhibit System Recovery | Shadow copies and backup/archive data were deleted to impede restoration.1 | 1 |
- Question
- What is Gunra?
- Question
- What is new?
- Answer
- AA26-222A adds government-observed edge exploitation, identity/session theft, cloud exfiltration, recovery destruction, and concrete IOCs.1
- Question
- Is Gunra the same as Conti?
- Question
- Does patching close the incident?
- Answer
- No. It closes a vulnerability path but does not remove stolen sessions, malicious accounts, altered authentication, or downstream access.1
- Question
- Does an IOC hit prove compromise?
- Answer
- No. Validate time, ownership, direction, process, identity, and adjacent behavior; CISA marks network infrastructure as potentially historical.1
- Question
- Should a victim pay?
- Answer
- The advisory discourages payment and stresses tested offline recovery and law-enforcement reporting; legal and operational decisions require case-specific counsel.1
- Question
- Who is behind Gunra?
- Answer
- The evidence supports a financially motivated Gunra operator and affiliates, including Golden Community branding, but not named people or state sponsorship.1
- Question
- Why should an SMB care?
- Answer
- Common VPN, Microsoft 365, NAS, database, backup, RDP, and outsourced-IT dependencies can turn one privileged foothold into broad interruption and data exposure.1
| Question | Answer |
|---|---|
| What is Gunra? | A criminal ransomware family and RaaS ecosystem that supports affiliates with cross-platform lockers and extortion infrastructure.1, 2, 3 |
| What is new? | AA26-222A adds government-observed edge exploitation, identity/session theft, cloud exfiltration, recovery destruction, and concrete IOCs.1 |
| Is Gunra the same as Conti? | No. The code is derived from or influenced by leaked Conti source; operator continuity is not established.1, 2 |
| Does patching close the incident? | No. It closes a vulnerability path but does not remove stolen sessions, malicious accounts, altered authentication, or downstream access.1 |
| Does an IOC hit prove compromise? | No. Validate time, ownership, direction, process, identity, and adjacent behavior; CISA marks network infrastructure as potentially historical.1 |
| Should a victim pay? | The advisory discourages payment and stresses tested offline recovery and law-enforcement reporting; legal and operational decisions require case-specific counsel.1 |
| Who is behind Gunra? | The evidence supports a financially motivated Gunra operator and affiliates, including Golden Community branding, but not named people or state sponsorship.1 |
| Why should an SMB care? | Common VPN, Microsoft 365, NAS, database, backup, RDP, and outsourced-IT dependencies can turn one privileged foothold into broad interruption and data exposure.1 |
- Item
- CVE-2024-55591
- Reference / Boundary
- FortiOS/FortiProxy authentication bypass observed by FBI as a Gunra initial-access path. Apply the vendor-fixed release and investigate historical exposure.1
- Sources
- 1
- Item
- CVE-2025-24472
- Reference / Boundary
- FortiOS/FortiProxy authentication bypass observed in the same campaign context; the exploit path can create forticloud-sync with superuser privileges.1
- Sources
- 1
| Item | Reference / Boundary | Sources |
|---|---|---|
| CVE-2024-55591 | FortiOS/FortiProxy authentication bypass observed by FBI as a Gunra initial-access path. Apply the vendor-fixed release and investigate historical exposure.1 | 1 |
| CVE-2025-24472 | FortiOS/FortiProxy authentication bypass observed in the same campaign context; the exploit path can create forticloud-sync with superuser privileges.1 | 1 |
| KEV interpretation | Both vulnerabilities are known-exploited edge risks, but a KEV or vulnerable version alone does not prove Gunra compromise or attribute an intrusion.1 | 1 |
| Other access paths | Credential exposure, SSH control weaknesses, default credentials, missing lockout, and session theft mean CVE-only hunting is insufficient.1 | 1 |
This public brief retains defensible detection and scoping observables, not raw attacker infrastructure or operational instructions. Validate against owned telemetry before blocking or attributing.
- Observable
- Attacker IP address
- Defender Use
- 23.239.119[.]2–6; 86.54.28[.]216; 103.125.234[.]14; 70.36.99[.]82; 211.21.210[.]181; 123.184.143[.]105; 182.204.21[.]240; 182.204.16[.]112; 123.244.187[.]144; 182.204.39[.]118; 67.43.53[.]10; 123.246.37[.]108; 91.201.66[.]146. CISA warns these are historical and must be vetted before blocking.1
- Sources
- 1
- Observable
- Attacker domain / FQDN
- Defender Use
- datapub[.]news plus the three defanged onion addresses in AA26-222A/STIX. Use for historical investigation; do not browse actor infrastructure from production systems.1
- Sources
- 1
- Observable
- SHA-256 — main.exe
- Defender Use
- 2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751 and 834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1; tools used to exfiltrate OneDrive/SharePoint.1
- Sources
- 1
- Observable
- SHA-256 — encryptors
- Defender Use
- 91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0 (cryptor.exe); a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9 (msmp.exe).1
- Sources
- 1
- Observable
- Malware filename / file name
- Observable
- Malicious account
- Defender Use
- forticloud-sync — a superuser account created on vulnerable Fortinet devices through the documented exploit path.1
- Sources
- 1
- Observable
- Behavioral pivots
- Defender Use
- Late-night 22:00–06:00 activity, log/history clearing, Impacket, NTDS dumping, RDP/SMB movement, SSH tunnels, archive creation, Mega/FileZilla/RClone transfer, OneDrive/SharePoint collection, WMI shadow-copy deletion, and backup destruction.1
- Sources
- 1
- Observable
- Attacker-controlled URL / malicious URL
- Defender Use
- Tor negotiation/DLS URLs and qTox contacts are published in AA26-222A and its STIX package. Preserve from evidence; do not connect from production or personal systems.1
- Sources
- 1
- Observable
- Negotiation emails
- Defender Use
- AA26-222A lists four defanged Proton/Gmail addresses associated with ransom negotiation. Treat as historical identifiers and preserve headers/context.1
- Sources
- 1
| Observable | Defender Use | Sources |
|---|---|---|
| Attacker IP address | 23.239.119[.]2–6; 86.54.28[.]216; 103.125.234[.]14; 70.36.99[.]82; 211.21.210[.]181; 123.184.143[.]105; 182.204.21[.]240; 182.204.16[.]112; 123.244.187[.]144; 182.204.39[.]118; 67.43.53[.]10; 123.246.37[.]108; 91.201.66[.]146. CISA warns these are historical and must be vetted before blocking.1 | 1 |
| Attacker domain / FQDN | datapub[.]news plus the three defanged onion addresses in AA26-222A/STIX. Use for historical investigation; do not browse actor infrastructure from production systems.1 | 1 |
| SHA-256 — main.exe | 2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751 and 834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1; tools used to exfiltrate OneDrive/SharePoint.1 | 1 |
| SHA-256 — encryptors | 91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0 (cryptor.exe); a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9 (msmp.exe).1 | 1 |
| Malware filename / file name | main.exe, cryptor.exe, msmp.exe, R3ADM3.txt, .ENCRT, and .CRYPT. Confirm path, signer, hash, creation time, parent process, and adjacent activity.1, 2 | 1, 2 |
| Malicious account | forticloud-sync — a superuser account created on vulnerable Fortinet devices through the documented exploit path.1 | 1 |
| Behavioral pivots | Late-night 22:00–06:00 activity, log/history clearing, Impacket, NTDS dumping, RDP/SMB movement, SSH tunnels, archive creation, Mega/FileZilla/RClone transfer, OneDrive/SharePoint collection, WMI shadow-copy deletion, and backup destruction.1 | 1 |
| Attacker-controlled URL / malicious URL | Tor negotiation/DLS URLs and qTox contacts are published in AA26-222A and its STIX package. Preserve from evidence; do not connect from production or personal systems.1 | 1 |
| Negotiation emails | AA26-222A lists four defanged Proton/Gmail addresses associated with ransom negotiation. Treat as historical identifiers and preserve headers/context.1 | 1 |
| qTox identifiers | Four long qTox IDs are published by the joint advisory. Match exact values from the STIX/advisory; do not manually contact them.1 | 1 |
| Dual-use tool cluster | FileZilla, Amass, RClone, Sliver, 7-Zip, WinRAR, DBeaver, Slack, VS Code, MobaXterm, AnyDesk, Google Remote Desktop, Mimikatz, and Impacket require timing, user, process, destination, and change correlation.1 | 1 |
- Actor / Label
- Gunra
- Attribution Boundary
- Criminal ransomware operator/ecosystem and malware label; the joint advisory uses 'Gunra actors' for observed activity.1
- Sources
- 1
- Actor / Label
- Golden Community
- Attribution Boundary
- Branding alias observed by FBI during RaaS expansion; not a separately proven organization.1
- Sources
- 1
- Actor / Label
- Gunra affiliates
- Actor / Label
- Conti
| Actor / Label | Attribution Boundary | Sources |
|---|---|---|
| Gunra | Criminal ransomware operator/ecosystem and malware label; the joint advisory uses 'Gunra actors' for observed activity.1 | 1 |
| Golden Community | Branding alias observed by FBI during RaaS expansion; not a separately proven organization.1 | 1 |
| Gunra affiliates | Independent financially motivated operators using service tooling. Tradecraft may differ across intrusions, so a Gunra artifact does not identify one affiliate.1, 3 | 1, 3 |
| Conti | Source-code lineage/influence only. No retained authoritative source says Gunra is Conti or identifies former Conti members as its operators.1, 2 | 1, 2 |
| State attribution | Not established. Tool or infrastructure overlap with another operation would require incident-specific corroboration and must not be converted into a state-sponsorship claim.1 | 1 |
- Audience
- Executives
- Decision-ready Point
- Gunra can turn one exposed edge device or administrator identity into data theft, business interruption, recovery failure, and regulatory/customer consequences.1
- Sources
- 1
- Audience
- SOC / IR
- Decision-ready Point
- Use the atomic IOCs to focus a behavior-led hunt across edge, identity, VDI, AD, cloud storage, endpoints, egress, and backups.1
- Sources
- 1
- Audience
- MSPs
- Decision-ready Point
- Prove scope per customer. Shared tooling creates plausible downstream access, but customer impact requires customer-specific evidence.1
- Sources
- 1
| Audience | Decision-ready Point | Sources |
|---|---|---|
| Executives | Gunra can turn one exposed edge device or administrator identity into data theft, business interruption, recovery failure, and regulatory/customer consequences.1 | 1 |
| SOC / IR | Use the atomic IOCs to focus a behavior-led hunt across edge, identity, VDI, AD, cloud storage, endpoints, egress, and backups.1 | 1 |
| MSPs | Prove scope per customer. Shared tooling creates plausible downstream access, but customer impact requires customer-specific evidence.1 | 1 |
| Insurance / counsel | Patch state is not incident closure. Ask what access occurred, which credentials/data/recovery systems were reachable, and what uncertainty remains.1 | 1 |
| Employees / partners | Report unusual remote-access prompts, repeated MFA requests, account lockouts, unexplained file extensions, ransom notes, or inaccessible shared data immediately; do not engage the actor.1 | 1 |
- Decision Owner
- CISO / executive
- Timeframe
- 0–4 hours
- Decision
- Authorize emergency exposure removal, evidence preservation, and incident command for affected or unknown edge systems.
- Success Evidence
- Named owner, asset/customer scope, containment decision, and preserved evidence inventory.1
- Decision Owner
- Network / vulnerability
- Timeframe
- 0–24 hours
- Decision
- Patch applicable Fortinet versions, restrict management, eliminate defaults, enforce lockout/MFA, and verify every edge account/config change.
- Decision Owner
- SOC / IR
- Timeframe
- 0–48 hours
- Decision
- Determine whether access, persistence, credential theft, exfiltration, encryption preparation, or recovery impairment occurred.
- Success Evidence
- Evidence-backed finding for each phase with documented retention gaps.1
- Decision Owner
- Identity / cloud
- Timeframe
- 0–48 hours
- Decision
- Revoke sessions, rotate reachable secrets, validate MFA/authentication code, and scope OneDrive/SharePoint and administrator access.
- Success Evidence
- No unexplained privileged identity/session; cloud access and data scope documented.1
- Decision Owner
- Backup / recovery
- Timeframe
- 0–72 hours
- Decision
- Protect recovery infrastructure and prove a clean, independent restoration path before reconnecting systems.
- Success Evidence
- Offline immutable copies, independent admin path, integrity validation, and tested restore.1
- Decision Owner
- Legal / privacy / insurer
- Timeframe
- As facts mature
- Decision
- Evaluate notice, contractual, regulatory, customer, and coverage obligations from verified access/data/impact evidence.
- Success Evidence
- Decision log tied to affected parties, evidence, uncertainty, and remediation proof.1
| Decision Owner | Timeframe | Decision | Success Evidence |
|---|---|---|---|
| CISO / executive | 0–4 hours | Authorize emergency exposure removal, evidence preservation, and incident command for affected or unknown edge systems. | Named owner, asset/customer scope, containment decision, and preserved evidence inventory.1 |
| Network / vulnerability | 0–24 hours | Patch applicable Fortinet versions, restrict management, eliminate defaults, enforce lockout/MFA, and verify every edge account/config change. | Fixed versions plus historical exposure and account/config review per appliance.1, 7 |
| SOC / IR | 0–48 hours | Determine whether access, persistence, credential theft, exfiltration, encryption preparation, or recovery impairment occurred. | Evidence-backed finding for each phase with documented retention gaps.1 |
| Identity / cloud | 0–48 hours | Revoke sessions, rotate reachable secrets, validate MFA/authentication code, and scope OneDrive/SharePoint and administrator access. | No unexplained privileged identity/session; cloud access and data scope documented.1 |
| Backup / recovery | 0–72 hours | Protect recovery infrastructure and prove a clean, independent restoration path before reconnecting systems. | Offline immutable copies, independent admin path, integrity validation, and tested restore.1 |
| Legal / privacy / insurer | As facts mature | Evaluate notice, contractual, regulatory, customer, and coverage obligations from verified access/data/impact evidence. | Decision log tied to affected parties, evidence, uncertainty, and remediation proof.1 |
- Technology / Trust Path
- Fortinet / VPN edge
- Risk / Defensive Priority
- Known vulnerabilities, default credentials, weak SSH controls, no lockout, and public administration can provide privileged entry.1
- Sources
- 1
- Technology / Trust Path
- Identity / VDI / AD
- Risk / Defensive Priority
- Stolen sessions, hashes, tickets, enterprise credentials, and authentication-code changes can survive simple endpoint cleanup.1
- Sources
- 1
- Technology / Trust Path
- Microsoft 365 data
- Risk / Defensive Priority
- OneDrive and SharePoint collection can create substantial notification and contractual scope before encryption begins.1
- Sources
- 1
| Technology / Trust Path | Risk / Defensive Priority | Sources |
|---|---|---|
| Fortinet / VPN edge | Known vulnerabilities, default credentials, weak SSH controls, no lockout, and public administration can provide privileged entry.1 | 1 |
| Identity / VDI / AD | Stolen sessions, hashes, tickets, enterprise credentials, and authentication-code changes can survive simple endpoint cleanup.1 | 1 |
| Microsoft 365 data | OneDrive and SharePoint collection can create substantial notification and contractual scope before encryption begins.1 | 1 |
| Backup / disaster recovery | Reachable recovery infrastructure may be deliberately destroyed; isolation and independent administration are essential.1 | 1 |
| Linux / databases / NAS | Cross-platform lockers and stolen server credentials expand impact beyond Windows workstations.1, 2 | 1, 2 |
- Tier
- Tier 0
- Sources / Disposition
- CISA joint advisory; CVE Program; MITRE ATT&CK
- Tier
- Tier 1
- Sources / Disposition
- Fortinet PSIRT; Microsoft Defender
- Tier
- Tier 2
- Sources / Disposition
- AhnLab ASEC; S2W
- Tier
- Tier 3
- Sources / Disposition
- NyxLab and independent security reporting
- Use in Brief
- Corroborating awareness only; consequential claims return to primary sources.8
- Tier
- Tier 4
- Sources / Disposition
- Public community, forums, DLS, and sample discussion
- Tier
- Tier 5
- Sources / Disposition
- No user-defined private source supplied
- Use in Brief
- Explicitly not used; no private telemetry or customer fact is implied.1
- Tier
- Tier 6
- Sources / Disposition
- No keyed custom integration used
- Use in Brief
- Explicitly not used; public evidence only.1
- Tier
- Tier 7
- Sources / Disposition
- CISA-linked STIX and primary-source follow-up
- Use in Brief
- Expanded the atomic indicator set without changing source authority.9
- Tier
- Tier 8
- Sources / Disposition
- AhnLab Linux analysis and reconciliation research
- Use in Brief
- Adds cross-platform and lineage detail while remaining subordinate to government observations.10
| Tier | Sources / Disposition | Use in Brief |
|---|---|---|
| Tier 0 | CISA joint advisory; CVE Program; MITRE ATT&CK | Controls government observations, canonical vulnerability identity, IOCs, and taxonomy.1, 5, 6 |
| Tier 1 | Fortinet PSIRT; Microsoft Defender | Vendor remediation/detection context; does not expand victim or actor scope.4, 7 |
| Tier 2 | AhnLab ASEC; S2W | Primary malware analysis and RaaS/dark-web development context.2, 3 |
| Tier 3 | NyxLab and independent security reporting | Corroborating awareness only; consequential claims return to primary sources.8 |
| Tier 4 | Public community, forums, DLS, and sample discussion | Discovery leads only; never sole alert or victim evidence.1, 3 |
| Tier 5 | No user-defined private source supplied | Explicitly not used; no private telemetry or customer fact is implied.1 |
| Tier 6 | No keyed custom integration used | Explicitly not used; public evidence only.1 |
| Tier 7 | CISA-linked STIX and primary-source follow-up | Expanded the atomic indicator set without changing source authority.9 |
| Tier 8 | AhnLab Linux analysis and reconciliation research | Adds cross-platform and lineage detail while remaining subordinate to government observations.10 |
- Issue
- New advisory versus existing IntelliOS coverage
- How IntelliOS Handles It
- Existing coverage was an actor/IOC enrichment record. AA26-222A adds observed intrusion mechanics, authoritative IOCs, mitigations, and current multi-agency assessment; a new PANDA brief and campaign card are justified.1
- Sources
- 1
- Issue
- First seen
- Issue
- Conti relationship
- Issue
- Victim counts
| Issue | How IntelliOS Handles It | Sources |
|---|---|---|
| New advisory versus existing IntelliOS coverage | Existing coverage was an actor/IOC enrichment record. AA26-222A adds observed intrusion mechanics, authoritative IOCs, mitigations, and current multi-agency assessment; a new PANDA brief and campaign card are justified.1 | 1 |
| First seen | FBI and AhnLab support April 2025. Later database first-seen dates reflect collection visibility and do not override primary reporting.1, 2 | 1, 2 |
| Conti relationship | Code is derived from or significantly influenced by leaked Conti source. This is technical lineage, not actor identity.1, 2 | 1, 2 |
| Victim counts | DLS listings and researcher samples describe observable claims, not a complete or independently verified victim census. This brief does not promote a numeric global total.1, 3 | 1, 3 |
| IOC age | CISA explicitly marks network indicators as potentially historical. Preserve first/last-seen context and corroborate before blocking or attributing.1 | 1 |
| Ransom-note spelling | CISA narrative publishes R3ADM3.txt; one ATT&CK table row renders R34DM3.txt. This brief uses the narrative and file-analysis form R3ADM3.txt and records the discrepancy here.1 | 1 |
- Contributor
- FBI, CISA, DC3, NSA, USSS, KNPA
- Role in This Brief
- What They Do: investigate, defend against, and publish authoritative guidance on cyber threats. Why They Matter Here: joint authors controlling observed TTPs, IOCs, mitigation, sectors, and attribution language.1
- Sources
- 1
- Contributor
- AhnLab Security Intelligence Center
- Role in This Brief
- What They Do: analyze malware and campaigns. Why They Matter Here: primary research supporting emergence, Conti-code comparison, encryptor behavior, and Linux analysis.2
- Sources
- 2
- Contributor
- S2W
- Role in This Brief
- What They Do: research dark-web and cybercrime ecosystems. Why They Matter Here: RaaS evolution and measured operational context, with explicit sample limitations.3
- Sources
- 3
| Contributor | Role in This Brief | Sources |
|---|---|---|
| FBI, CISA, DC3, NSA, USSS, KNPA | What They Do: investigate, defend against, and publish authoritative guidance on cyber threats. Why They Matter Here: joint authors controlling observed TTPs, IOCs, mitigation, sectors, and attribution language.1 | 1 |
| AhnLab Security Intelligence Center | What They Do: analyze malware and campaigns. Why They Matter Here: primary research supporting emergence, Conti-code comparison, encryptor behavior, and Linux analysis.2 | 2 |
| S2W | What They Do: research dark-web and cybercrime ecosystems. Why They Matter Here: RaaS evolution and measured operational context, with explicit sample limitations.3 | 3 |
| Microsoft | What They Do: operate Defender threat detection and publish malware records. Why They Matter Here: detection corroboration; the record does not independently establish campaign scope.4 | 4 |
| MITRE ATT&CK | What They Do: maintain adversary-behavior taxonomy. Why They Matter Here: supplies the lifecycle vocabulary referenced by the joint advisory; taxonomy does not prove local execution.5 | 5 |
- Example
- Government-observed victims
- What It Shows / Boundary
- The advisory reports victims across government, healthcare, finance/insurance, manufacturing/construction, transportation/logistics, utilities, academia, media/communications, retail, and professional/nonprofit services, but does not publish a complete named list.1
- Sources
- 1
- Example
- Gunra DLS listings
| Example | What It Shows / Boundary | Sources |
|---|---|---|
| Government-observed victims | The advisory reports victims across government, healthcare, finance/insurance, manufacturing/construction, transportation/logistics, utilities, academia, media/communications, retail, and professional/nonprofit services, but does not publish a complete named list.1 | 1 |
| Gunra DLS listings | Actor-posted listings and previews support the extortion model but are claims until independently verified; listings may include phantom or exaggerated entries.1, 3 | 1, 3 |
| Case-level examples | The joint advisory describes incidents involving VDI, AD, OneDrive/SharePoint, database servers, NAS, and primary/DR backups without identifying the organizations.1 | 1 |
| Named victims in this brief | None. IntelliOS does not infer affected organizations from product ownership, sector, IOC contact, or leak-site assertions alone.1 | 1 |
Only explicitly public vendor or organization disclosures belong here. The rows below describe the public record and do not represent an affected-party list.
- Disclosure / Affected Set
- Government-observed victims
- Disclosure Boundary
- The advisory reports victims across government, healthcare, finance/insurance, manufacturing/construction, transportation/logistics, utilities, academia, media/communications, retail, and professional/nonprofit services, but does not publish a complete named list.1
- Sources
- 1
- Disclosure / Affected Set
- Gunra DLS listings
| Disclosure / Affected Set | Disclosure Boundary | Sources |
|---|---|---|
| Government-observed victims | The advisory reports victims across government, healthcare, finance/insurance, manufacturing/construction, transportation/logistics, utilities, academia, media/communications, retail, and professional/nonprofit services, but does not publish a complete named list.1 | 1 |
| Gunra DLS listings | Actor-posted listings and previews support the extortion model but are claims until independently verified; listings may include phantom or exaggerated entries.1, 3 | 1, 3 |
| Case-level examples | The joint advisory describes incidents involving VDI, AD, OneDrive/SharePoint, database servers, NAS, and primary/DR backups without identifying the organizations.1 | 1 |
| Named victims in this brief | None. IntelliOS does not infer affected organizations from product ownership, sector, IOC contact, or leak-site assertions alone.1 | 1 |
Known-exploited status drives prioritization, but local response depends on exposure and evidence rather than catalog membership alone.
- Asset State
- Historically internet-reachable edge
- Priority
- Incident investigation
- Asset State
- Version or reachability unknown
- Priority
- Emergency inventory
- Asset State
- Fixed before exposure window
- Priority
- Verification
- Asset State
- IOC or behavioral hit
- Priority
- Corroboration and containment
- Required Outcome
- Validate timing, ownership, direction, user/process/session context, then contain and expand scope based on confirmed behavior.1
- Asset State
- MSP/shared administration
- Priority
- Per-customer scoping
- Required Outcome
- Map reachable tenants and separately document access, affected systems/data, remediation, notice, and closure evidence.1
| Asset State | Priority | Required Outcome |
|---|---|---|
| Historically internet-reachable edge | Incident investigation | Preserve telemetry, establish the exposure window, review accounts/configuration, and determine whether privileged access occurred.1, 7 |
| Version or reachability unknown | Emergency inventory | Resolve owner, model, branch, build, management path, and customer/tenant reach; isolate when uncertainty cannot be safely resolved.1, 7 |
| Fixed before exposure window | Verification | Retain proof of installation and access controls; confirm no separate credential, SSH, session, or remote-service path applies.1, 7 |
| IOC or behavioral hit | Corroboration and containment | Validate timing, ownership, direction, user/process/session context, then contain and expand scope based on confirmed behavior.1 |
| MSP/shared administration | Per-customer scoping | Map reachable tenants and separately document access, affected systems/data, remediation, notice, and closure evidence.1 |
- Lifecycle Phase
- Initial access
- Observed Gunra Evidence
- Fortinet CVEs, credential exposure, default VPN credentials, weak SSH and lockout controls.
- Detection / Interruption
- Patch, restrict edge administration, MFA/lockout, and historical access review.1
- Lifecycle Phase
- Persistence / privilege
- Observed Gunra Evidence
- forticloud-sync, altered accounts, OpenSSH tunnels, stolen sessions, and OTP bypass.
- Detection / Interruption
- Account/config diff, session revocation, code integrity, and tunnel hunting.1
- Lifecycle Phase
- Credential access / movement
- Observed Gunra Evidence
- secretsdump.py, NTDS hashes, pass-the-hash/ticket, SMB, RDP, and VDI pivots.
- Detection / Interruption
- AD/VDI telemetry, privileged credential reset, lateral-flow review, and segmentation.1
- Lifecycle Phase
- Collection
- Observed Gunra Evidence
- Business files, databases, PII, email, and configuration documents.
- Detection / Interruption
- File, mail, database, cloud, and administrator-workstation audit.1
- Lifecycle Phase
- Exfiltration
- Observed Gunra Evidence
- main.exe, OneDrive/SharePoint, archives, Mega, RClone, and FileZilla.
- Detection / Interruption
- Cloud audit, archive/process telemetry, proxy/DNS/egress, and DLP correlation.1
- Lifecycle Phase
- Impact
- Observed Gunra Evidence
- Windows/Linux encryption, .ENCRT/.CRYPT, R3ADM3.txt, shadow-copy and backup deletion.
| Lifecycle Phase | Observed Gunra Evidence | Detection / Interruption |
|---|---|---|
| Initial access | Fortinet CVEs, credential exposure, default VPN credentials, weak SSH and lockout controls. | Patch, restrict edge administration, MFA/lockout, and historical access review.1 |
| Persistence / privilege | forticloud-sync, altered accounts, OpenSSH tunnels, stolen sessions, and OTP bypass. | Account/config diff, session revocation, code integrity, and tunnel hunting.1 |
| Credential access / movement | secretsdump.py, NTDS hashes, pass-the-hash/ticket, SMB, RDP, and VDI pivots. | AD/VDI telemetry, privileged credential reset, lateral-flow review, and segmentation.1 |
| Collection | Business files, databases, PII, email, and configuration documents. | File, mail, database, cloud, and administrator-workstation audit.1 |
| Exfiltration | main.exe, OneDrive/SharePoint, archives, Mega, RClone, and FileZilla. | Cloud audit, archive/process telemetry, proxy/DNS/egress, and DLP correlation.1 |
| Impact | Windows/Linux encryption, .ENCRT/.CRYPT, R3ADM3.txt, shadow-copy and backup deletion. | Behavior blocking, rapid isolation, immutable backups, and staged clean recovery.1, 2 |
- Weight
- Controlling
- Source Class
- Joint government advisory
- Controls / Does Not Control
- Observed campaign TTPs, IOCs, sectors, mitigations, and bounded Gunra attribution.1
- Weight
- Primary technical
- Source Class
- AhnLab / vendor records
- Weight
- High-value research
- Source Class
- S2W
- Controls / Does Not Control
- RaaS and dark-web development within its observed sample; not a global census.3
- Weight
- Taxonomy
- Source Class
- MITRE ATT&CK / CVE
- Weight
- Discovery only
- Source Class
- News, community, DLS, forums
| Weight | Source Class | Controls / Does Not Control |
|---|---|---|
| Controlling | Joint government advisory | Observed campaign TTPs, IOCs, sectors, mitigations, and bounded Gunra attribution.1 |
| Primary technical | AhnLab / vendor records | Sample behavior, emergence, platform, and detection; not universal affiliate behavior.2, 4 |
| High-value research | S2W | RaaS and dark-web development within its observed sample; not a global census.3 |
| Taxonomy | MITRE ATT&CK / CVE | Technique and vulnerability identifiers; not local incident proof.5, 6 |
| Discovery only | News, community, DLS, forums | Leads and corroboration only; never sole proof of victim, actor, or loss.1, 3 |
CARDS Threat Actor
Gunra
Existing Gunra operator/malware profile, reconciled with the new joint advisory.
CARDS Campaign
Gunra RaaS Edge-Exploitation Campaign
Campaign-level view of the 2025–2026 access, credential, exfiltration, encryption, and extortion lifecycle.
PANDA Flash Threat Intel Brief
FortiBleed Credential Exposure
Separate Fortinet credential-exposure reporting; related defensive context, not the same campaign.
PANDA Sector Risk Brief
Ransomware Targeting U.S. SMBs in 2026
Portfolio-level SMB ransomware exposure and prevention context.
Published research notes
Public, read-only, source-backed context retained with this brief. No account or sign-in is required.
Confirmed
RaaS expansion, double extortion, observed edge exploitation, credential/session theft, MFA bypass, lateral movement, cloud exfiltration, Windows/Linux encryption, recovery inhibition, and the listed IOCs are source-backed.1
Assessment
SMB/MSP blast radius, insurance materiality, and response priority depend on local exposure, trust paths, data, and recovery architecture.1
Unknown
Named operator identities, citizenship, state sponsorship, one universal affiliate playbook, a complete victim count, and the current control of historical infrastructure remain unestablished.1, 3
IntelliOS reconciliation
No prior PANDA Gunra brief or dedicated campaign card existed. The pre-existing Gunra actor record is retained and enriched rather than duplicated.1, 2, 3
Operational safety
Do not contact actor infrastructure, upload sensitive evidence to public scanners, or block historical shared infrastructure without validation. Preserve evidence and coordinate containment with incident response, counsel, insurer, and service providers as appropriate.1
- #
- 1
- Tier
- Tier 0 - Most Trusted
- Publisher
- CISA / FBI / DC3 / NSA / USSS / KNPA
- Published
- Aug. 10, 2026
- Why Used
- Controlling source for observed campaign mechanics, CVEs, IOCs, mitigations, sectors, and attribution language.
- #
- 2
- Tier
- Tier 2 - High-Value Research
- Publisher
- AhnLab Security Intelligence Center
- Published
- July 23, 2025
- Why Used
- Primary malware research for April emergence, Conti-code similarity, encryption, ransom workflow, and early artifacts.
- #
- 3
- Tier
- Tier 2 - High-Value Research
- Publisher
- S2W
- Published
- May 13, 2026
- Why Used
- RaaS evolution, dark-web recruitment, operational measurement, and sampling boundaries.
- #
- 4
- Tier
- Tier 1 - Authoritative
- Publisher
- Microsoft
- Published
- June 8, 2025
- Why Used
- Vendor detection corroboration; not used to expand campaign scope.
- Source
- Ransom:Win64/Gunra!rfn
- #
- 5
- Tier
- Tier 0 - Most Trusted
- Publisher
- MITRE ATT&CK
- Published
- Version 19.1; checked Aug. 11, 2026
- Why Used
- Taxonomy for observed behaviors mapped by the joint advisory.
- Source
- Enterprise ATT&CK
- #
- 6
- Tier
- Tier 0 - Most Trusted
- Publisher
- CVE Program
- Published
- Checked Aug. 11, 2026
- Why Used
- Canonical vulnerability identifiers and affected-product references; campaign use remains controlled by the joint advisory.
- #
- 7
- Tier
- Tier 1 - Authoritative
- Publisher
- Fortinet PSIRT
- Published
- Checked Aug. 11, 2026
- Why Used
- Vendor remediation context for the government-observed initial-access vulnerabilities.
- #
- 8
- Tier
- Tier 3 - Corroborating News
- Publisher
- NyxLab
- Published
- Feb. 2026
- Why Used
- Corroborating targeting and access-path awareness; not used to establish a controlling claim.
- #
- 9
- Tier
- Tier 7 - Inner Discovery
- Publisher
- CISA
- Published
- Aug. 10, 2026
- Why Used
- Machine-readable indicator expansion directly linked by the controlling advisory.
- Source
- AA26-222A STIX JSON
- #
- 10
- Tier
- Tier 8 - Expansion Research / AI Agent Delta
- Publisher
- AhnLab ASEC
- Published
- Oct. 22, 2025
- Why Used
- Expansion research supporting Linux behavior and cross-platform boundaries; subordinate to current government observations.
| # | Tier | Publisher | Published | Why Used | Source |
|---|---|---|---|---|---|
| 1 | Tier 0 - Most Trusted | CISA / FBI / DC3 / NSA / USSS / KNPA | Aug. 10, 2026 | Controlling source for observed campaign mechanics, CVEs, IOCs, mitigations, sectors, and attribution language. | AA26-222A — #StopRansomware: Gunra Ransomware |
| 2 | Tier 2 - High-Value Research | AhnLab Security Intelligence Center | July 23, 2025 | Primary malware research for April emergence, Conti-code similarity, encryption, ransom workflow, and early artifacts. | Gunra Ransomware Emerges with New DLS |
| 3 | Tier 2 - High-Value Research | S2W | May 13, 2026 | RaaS evolution, dark-web recruitment, operational measurement, and sampling boundaries. | Gunra Ransomware Group Activity and RaaS Expansion |
| 4 | Tier 1 - Authoritative | Microsoft | June 8, 2025 | Vendor detection corroboration; not used to expand campaign scope. | Ransom:Win64/Gunra!rfn |
| 5 | Tier 0 - Most Trusted | MITRE ATT&CK | Version 19.1; checked Aug. 11, 2026 | Taxonomy for observed behaviors mapped by the joint advisory. | Enterprise ATT&CK |
| 6 | Tier 0 - Most Trusted | CVE Program | Checked Aug. 11, 2026 | Canonical vulnerability identifiers and affected-product references; campaign use remains controlled by the joint advisory. | CVE-2024-55591 and CVE-2025-24472 records |
| 7 | Tier 1 - Authoritative | Fortinet PSIRT | Checked Aug. 11, 2026 | Vendor remediation context for the government-observed initial-access vulnerabilities. | FortiOS/FortiProxy authentication-bypass advisories |
| 8 | Tier 3 - Corroborating News | NyxLab | Feb. 2026 | Corroborating targeting and access-path awareness; not used to establish a controlling claim. | Increased Gunra Ransomware Operations |
| 9 | Tier 7 - Inner Discovery | CISA | Aug. 10, 2026 | Machine-readable indicator expansion directly linked by the controlling advisory. | AA26-222A STIX JSON |
| 10 | Tier 8 - Expansion Research / AI Agent Delta | AhnLab ASEC | Oct. 22, 2025 | Expansion research supporting Linux behavior and cross-platform boundaries; subordinate to current government observations. | Linux Version of Gunra Ransomware |
- Version
- v1.0
- Date
- Aug 11, 2026
- Changes
- Initial 32-card release. Reconciles the Aug. 10 joint U.S./Republic of Korea advisory with prior malware research and the existing IntelliOS Gunra actor record; adds a dedicated campaign card, concrete IOCs, attribution limits, and response decisions.
| Version | Date | Changes |
|---|---|---|
| v1.0 | Aug 11, 2026 | Initial 32-card release. Reconciles the Aug. 10 joint U.S./Republic of Korea advisory with prior malware research and the existing IntelliOS Gunra actor record; adds a dedicated campaign card, concrete IOCs, attribution limits, and response decisions. |
