IC Technology & Cyber — 2026-08-12

CISA NSA FBI and South Korean Police Issue Joint Advisory on Gunra Ransomware Targeting Critical Infrastructure

BLUFGunra's pivot to a full RaaS affiliate model compounds exposure for critical infrastructure operators who have left year-old FortiOS flaws unpatched, converting a known vulnerability into an active compromise pipeline.

The FBI, CISA, NSA, DOD Cyber Crime Center, US Secret Service, and South Korea's National Police Agency issued a joint advisory on Monday detailing Gunra ransomware, first observed by the FBI in April 2025 and derived from leaked Conti source code 1. The advisory states Gunra expanded into a ransomware-as-a-service affiliate program in January 2026, offering builders and Windows/Linux payloads under the alias Golden Community, and has recruited penetration testers as initial access brokers 12. Investigators linked initial access to exploitation of two FortiOS/FortiProxy authentication-bypass flaws, CVE-2024-55591 and CVE-2025-24472, along with abused default credentials and MFA bypass via attacker-controlled one-time passwords 1. The FBI reported one victim lost tens of terabytes of data exfiltrated via a malicious tool targeting OneDrive and SharePoint, with stolen files uploaded to Mega, and said Gunra encrypts using ChaCha20 and RSA-4096 while giving victims five to seven days to negotiate via Tor or qTox 2.

Analysis
The advisory reads less as novel disclosure than as a patching mandate: both exploited FortiOS/FortiProxy flaws have been public over a year, so continued compromise reflects unremediated exposure rather than new attack surface. A lagging population of unpatched appliances rather than any new Gunra capability could equally explain the pattern. Gunra's shift into a structured RaaS model, with recruited penetration testers acting as access brokers, lowers the technical bar for follow-on intrusions against that same unpatched base, compounding risk for operators still running default credentials or unsegmented VPN and VDI environments. The tens-of-terabyte OneDrive and SharePoint exfiltration case shows double extortion now reaching cloud collaboration platforms, not just on-premises file shares. CISA's advisory is the sole primary source; other outlets merely republish it.
4 sources
  1. #StopRansomware: Gunra Ransomware - CISA
  2. FBI warns Gunra ransomware targets critical sectors and governments - Cyber Insider
  3. Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure - The Register
  4. CISA, FBI Warn Gunra Ransomware Actors Targeting Critical Infrastructure - HSToday

View in full brief →

UNCLASSIFIED // OPEN SOURCE