#StopRansomware: Gunra Ransomware
Gunra ransomware expands to RaaS operations, targeting government and critical infrastructure with double-extortion
Summary
The Gunra ransomware, first seen in 2025 and evolving into a RaaS model in 2026, targets government and critical infrastructure organizations. It employs a double-extortion strategy, encrypting data and threatening to leak exfiltrated information. The advisory provides technical details and mitigation guidance, including patching vulnerabilities and implementing robust backups.
Full text
Cybersecurity Advisory #StopRansomware: Gunra Ransomware Release DateAugust 10, 2026 Alert CodeAA26-222A Related topics: Cybersecurity Best Practices , Critical Infrastructure Security and Resilience , Cyber Threats and Response Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra. Key Actions Prioritize patching known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure. Implement and test offline, immutable backups stored in a physically separate, segmented location to ensure recoverability without ransom payment. Segment networks to restrict lateral movement from an initially compromised device to other systems in the organization. Indicators of Compromise For a downloadable copy of indicators of compromise, see: AA26-222A STIX XML (54 KB) AA26-222A STIX JSON (61 KB) Intended Audience Organizations: Government, Critical Infrastructure Sectors: Healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services. Roles: Cybersecurity architects, defensive cybersecurity analysts, vulnerability analysts, systems administrators, and security systems managers. Introduction Note: This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources. The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Department of Defense Cyber Crime Center (DC3), National Security Agency (NSA), U.S. Secret Service (USSS), and Republic of Korea’s National Police Agency (KNPA)—hereafter referred to as “the authoring agencies”—are releasing this joint advisory to alert organizations to the emerging Gunra ransomware threat and to provide detection and mitigation guidance. Gunra first emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti1 ransomware source code. As of early 2026, Gunra expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums to financially motivated cybercriminals. Gunra actors demand ransom via a customized, Tor-based negotiation portal and threaten to publish exfiltrated data on a dedicated leak site (DLS) if victims do not comply. Gunra victims observed on the actors’ DLS span organizations across multiple sectors in the Americas, Europe, Middle East, Africa, and the Asia-Pacific.2 These sectors include: Healthcare and public health Financial services and insurance Critical manufacturing and construction Transportation systems and logistics Government services and facilities Utilities Academia Media and communications Retail Professional and nonprofit services The authoring agencies encourage organizations to implement the recommendations in the Mitigations section of this advisory to mitigate cyber threats related to Gunra ransomware, including: Prioritizing patching known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure. Implementing and testing offline, immutable backups stored in a physically separate, segmented location to ensure recoverability without ransom payment. Segmenting networks to restrict lateral movement from an initially compromised device to other systems in the organization. Download the PDF version of this report: AA26-222A StopRansomware Gunra Ransomware (PDF, 1.07 MB ) For a downloadable copy of IOCs, see: AA26-222A STIX XML (XML, 54.18 KB ) AA26-222A STIX JSON (JSON, 61.00 KB ) Technical Details Note: This advisory uses the MITRE ATT&CK® Matrix for Enterprise framework, version 19.1. See the MITRE ATT&CK Tactics and Techniques section of this advisory for a table of the threat actors’ activity mapped to MITRE ATT&CK tactics and techniques. Overview The FBI originally observed Gunra ransomware in April 2025. The threat actors quickly established a DLS on the Tor network to list victims and publish exfiltrated data. As of January 2026, Gunra launched a formal RaaS affiliate program on dark web forums, providing affiliates with access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation.3 The FBI observed the group adopting new branding aliases (notably operating under the name Golden Community) to support this expansion. Gunra has further commercialized its platform by actively recruiting penetration testers and ethical hackers to serve as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access. Based on FBI observations, Gunra actors use a traditional double-extortion model, exfiltrating sensitive victim data prior to encryption and threatening to publish the leaked data on their DLS unless the ransom is paid. Victims receive a ransom note in every affected directory guiding them to a Tor-based negotiation portal where they are assigned a Client ID and an initial password. Subsequently, victims receive instructions to contact the Gunra actors via qTox (an encrypted messaging application) to negotiate ransom payments within five to seven days. If the ransom is not paid, Gunra actors threaten to sell victim data on the DLS. Gunra ransomware appears to be based on, or significantly influenced by, the Conti ransomware source code leaked in 2022.4 Initially, Gunra actors’ campaigns focused on Windows environments; reporting in mid-2025 indicated the group introduced a Linux variant and moved toward broader cross-platform targeting.5 Initial Access The FBI observed Gunra actors obtaining initial access [TA0001] primarily through the exploitation of known vulnerabilities in internet-facing devices [T1190], including firewall and VPN appliances. The FBI observed exploits based on the following Common Vulnerabilities and Exposures (CVEs): CVE-2024-55591 [CWE-288: Authentication Bypass Using an Alternate Path or Channel]: Authentication bypass vulnerability affecting specific FortiOS and FortiProxy versions (see CVE record for more details). CVE-2025-24472 [CWE-288: Authentication Bypass Using an Alternate Path or Channel]: Authentication bypass vulnerability affecting specific FortiOS and FortiProxy versions (see CVE record for more details). Additionally, for initial access, KNPA observed Gunra actors exploit credential-exposure and Secure Shell (SSH) access control vulnerabilities in internet-facing VPN gateways to gain unauthorized remote access. Execution Gunra’s Windows encryptor relies on native operating system (OS) application programming interfaces (APIs) to drive both execution and targeted encryption activity. The binary uses the FindFirstFileW/FindNextFileW API calls [T
Indicators of Compromise
- cve — CVE-2024-55591
- cve — CVE-2025-24472
- ip — 23.239.119.2
- ip — 23.239.119.3
- ip — 23.239.119.4
- ip — 23.239.119.5
- ip — 23.239.119.6
- ip — 86.54.28.216
- ip — 103.125.234.14
- ip — 70.36.99.82
- ip — 211.21.210.181
- ip — 123.184.143.105
- ip — 182.204.21.240
- ip — 182.204.16.112
- ip — 123.244.187.144
- ip — 182.204.39.118
- ip — 67.43.53.10
- ip — 123.246.37.108
- ip — 91.201.66.146
- domain — datapub.news
- domain — gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad.onion
- domain — lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd.onion
- domain — nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd.onion
- email — a00f105546345756@proton.me
- email — 4569f6322bc3b22e9@proton.me
- email — ilovemycubscout@gmail.com
- email — 6449a3c1e612168526@proton.me
- hash_sha256 — 2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751
- hash_sha256 — 834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1
- hash_sha256 — 91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0
- hash_sha256 — a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9