TL;DR: Gunra is a ransomware-as-a-service (RaaS) variant built from the Conti source code leaked in 2022 and first observed by the FBI in April 2025 [1]. The August 10, 2026 joint advisory AA26-222A from FBI, CISA, NSA, USSS, DC3, and the Republic of Korea National Police Agency describes Gunra as targeting government, healthcare, financial services, manufacturing, transportation, utilities, academia, media, retail, and nonprofit organizations across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific [1]. Gunra actors exploit CVE-2024-55591 and CVE-2025-24472 (authentication bypass affecting FortiOS and FortiProxy) and create a malicious Fortinet super-user account named "forticloud-sync" with a hard-coded password [1]. Gunra uses ChaCha20 + RSA-4096 encryption, drops a ransom note named R3ADM3.txt, appends the .ENCRT extension to encrypted files, and exfiltrates data to the Mega file-sharing service [1]. HIPAA Journal reports the Gunra dark web leak site lists more than 30 worldwide victims, and that Gunra offers affiliates an 80 percent cut of any generated ransom [2]. The Record reports that Q2 2026 saw at least four industrial sector attacks attributed to Gunra, and that CISA acting executive assistant director Chris Butera framed Gunra as part of an ongoing trend of ransomware attacks causing disruption and harm [3]. This tracker is the running list: every confirmed detail from the AA26-222A advisory, every CVE, every named tool. Updated as cases develop.
What Gunra Actually Is
Gunra is a ransomware-as-a-service brand, not a single hacker. The developers run the leak site, the negotiation chat, and the payment infrastructure. Affiliates do the intrusions and split the proceeds. CISA's advisory AA26-222A places the first known activity in April 2025, when the FBI observed the ransomware and its leak site [1]. The encryptor is built from the Conti ransomware source code that leaked in 2022 [1][2]. That code leak gave every new entrant in the ransomware space a head start, and Gunra is built on it directly.
Two things made Gunra matter in 2026. First, the targeting pattern. The August 10, 2026 advisory lists healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services as the named sectors [1]. Healthcare is one of the named critical-infrastructure sectors, and the American Hospital Association carried an August 11, 2026 headline alert on Gunra [4]. Second, the affiliate model matured. The advisory documents that Gunra launched a formal RaaS affiliate program on dark web forums in January 2026, with a management panel, a configurable ransomware builder, cross-platform locker payloads, structured affiliate documentation, and a recruiting pipeline aimed at penetration testers and ethical hackers willing to serve as initial access brokers [1]. The affiliate cut is reported at 80 percent of any generated ransom, with the operators keeping 20 percent [2].
Gunra actors also adopted the alias "Golden Community" as part of the same RaaS expansion [1]. The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments, with limited success [3]. HIPAA Journal reports the dark web leak site currently lists more than 30 worldwide victims as of August 2026 [2].
Confirmed Victims (So Far)
AA26-222A does not name individual victim organizations by company. The advisory describes victim sectors, geographic regions, and the techniques Gunra used against them [1]. CISA, the FBI, and partner agencies are working from FBI investigations, leak-site posts, and third-party incident reports. The publicly disclosed picture so far:
More Than 30 Worldwide Victims on the Leak Site (As of August 2026)
The most concrete public tally is the dark web leak site listing reported in HIPAA Journal on August 11, 2026: more than 30 worldwide victims currently listed [2]. The advisory does not publish the same number from FBI investigations, and CISA, the FBI, NSA, USSS, DC3, and the Korean National Police Agency all note that the count grows as Gunra operations continue [1].
Q2 2026 Industrial Sector Attacks
Dragos data published through The Record reports at least four industrial sector attacks attributed to Gunra in Q2 2026, against a Q2 2026 backdrop of 1,140 ransomware incidents affecting industrial organizations [3]. Dragos also reported a 12 percent increase in industrial ransomware incidents from Q1 to Q2 2026 [3]. The Record does not name the four industrial organizations by company.
Sectors Hit (Per AA26-222A)
The advisory names the following sectors as targets across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific [1]:
- Healthcare and public health
- Financial services and insurance
- Critical manufacturing and construction
- Transportation systems and logistics
- Government services and facilities
- Utilities
- Academia
- Media and communications
- Retail
- Professional and nonprofit services
Healthcare is one of the sectors named in AA26-222A, and the American Hospital Association carried the advisory as a headline alert on August 11, 2026 [4]. No named hospital victims are publicly disclosed in AA26-222A or in the AHA coverage.
The Playbook: How Gunra Gets In And Holds You Hostage
The advisory AA26-222A documents the full technique chain in detail [1]. The core entry vectors and tradecraft:
- Two FortiOS and FortiProxy authentication bypasses. Gunra affiliates exploit CVE-2024-55591 and CVE-2025-24472 against unpatched FortiOS and FortiProxy appliances [1]. Both are catalogued as CWE-288 authentication-bypass-by-issues affecting access control. Once in, they create a Fortinet super-user account named "forticloud-sync" with a hard-coded password via the scheduled task, and use it for persistent administrative access [1]. KNPA separately reports Gunra actors exploit credential-exposure and SSH access control vulnerabilities in internet-facing VPN gateways [1].
- Encrypted messaging and direct outreach. The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments, with limited success [3]. Negotiation also flows through qTox encrypted messaging and a Tor-based negotiation panel where victims are assigned a Client ID and an initial password [1]. The advisory puts the standard negotiation window at five to seven days [1]. HIPAA Journal reports victims are given between five and ten days to commence negotiations [2].
- Credential dumping with Impacket and Mimikatz. Gunra actors use secretsdump.py (Impacket) for NTDS.dit credential dumping, then move laterally with pass-the-hash and pass-the-ticket [1]. Mimikatz is on the menu for obvious use. The advisory documents the actors stealing a symmetric encryption key from a Hiware system access control server to decrypt stored credentials [1].
- VDI session hijacking and MFA bypass. Gunra actors stole VDI session cookies for session hijacking, then modified the VDI authentication portal to bypass MFA via a Gunra-designated one-time password value [1]. That is a notable break from the usual playbook, where MFA bypass comes from social-engineering the help desk. Here, the actors rewrote the authentication portal itself.
- Living off the land. FileZilla, Amass, RClone, Sliver, 7-Zip, WinRAR, DBeaver, Slack, Microsoft Visual Studio Code, MobaXterm, AnyDesk, and Google Remote Desktop are on the CISA list of leveraged tools [1]. None of these are malware-only. They are the same legitimate admin and remote-management tools your IT team probably already uses.
- Operational timing. Gunra conducts malicious activities and internal infrastructure reconnaissance during late-night and early-morning hours, defined as 10:00 p.m. through 06:00 a.m. local time [1]. The malware uses the IsDebuggerPresent API for anti-debugging and excludes C:\Windows, C:\Program Files, and C:\Program Files (x86) from encryption, so the victim machine can still boot after encryption [1].
- Defense impairment and shadow-copy deletion. Volume shadow copies are deleted via WMI: cmd.exe invokes WMIC.exe against the shadowcopy object with a where clause selecting by the shadow copy identifier, then the delete verb runs [1]. Backup and archived data at primary and disaster recovery centers are deleted by the actors [1]. The two together kill the usual recovery path.
- Exfiltration via Mega. Stolen data goes out to the Mega file-sharing service, with the actors exfiltrating up to tens of terabytes [1]. Data exfiltrated includes business-critical documents, databases, personally identifiable information, and internal email communications including from Microsoft OneDrive and SharePoint [1][2]. Two main.exe binaries are on the CISA hash list for OneDrive and SharePoint exfiltration [1].
- Encryption. The encryptor uses ChaCha20 with RSA-4096 in a multi-threaded architecture that supports parallel encryption of multiple files simultaneously [1]. The Windows variant appends the .ENCRT extension; a July 2025 sample appended the .CRYPT extension [1]. The Linux ELF variant appends the .GNRA extension [1]. The ransom note is dropped as R3ADM3.txt in each affected directory [1][2]. The Tor-based panel gives each victim a Client ID and initial password for negotiation.
- Initial ransom asks. The advisory documents that Gunra "generally started negotiations at arbitrarily high ransom amounts (over tens of millions in US dollars)" [1]. HIPAA Journal reports that ransom demands in individual disclosures have exceeded $10 million [2]. No individual ransom payment amounts are disclosed in AA26-222A [1].
- Linux variant weakness. As of March 2026, researchers identified a weakness in the Gunra ransomware Linux ELF variants appended with .GNRA: the encryption keys use a weak pseudorandom number generator (PRNG) seeded with the predictable system srand(time(NULL)) [1]. Researchers reported the weakness allows key recovery using file timestamps and recovery of files without paying the ransom [2][3]. This is a real defensive opportunity that does not apply to the Windows .ENCRT variant.
- Dedicated leak site timeline. The Datapub.news clearnet mirror operated from June through July 2025 [1]. The Tor DLS moved to a new .onion address by March 2026 and to another by July 2026 [1]. The actors operate under the alias "Golden Community" to support RaaS expansion [1].
The single biggest lesson from AA26-222A is also the most boring one. Patching internet-facing FortiOS and FortiProxy appliances against CVE-2024-55591 and CVE-2025-24472 kills the most reliable initial access paths. The advisory puts it near the top. The rest of the mitigations, segmented offline backups, phishing-resistant MFA, least privilege, EDR, restrict RDP, audit admin accounts, and disable command-line and scripting permissions where feasible, are the same list every CISA advisory writes. They are the same list because they are the things that work.
What You Can Do If You Are A Gunra Victim
If you got a ransom note, a leak-site countdown, or a notification from a Gunra-hit vendor or partner, take the offered identity protection. Then add these steps:
- Do not pay if there is any other option. CISA, the FBI, and partner agencies state that "payment does not guarantee victim files will be recovered" and that payment may encourage further targeting. The Linux variant's PRNG weakness gives victims hit on Linux/ESXi infrastructure a real recovery path that does not involve paying the ransom [1][2][3].
- Audit your Fortinet appliances immediately. If you run FortiOS or FortiProxy, check whether you have an unrecognized super-user account named "forticloud-sync" with a hard-coded password via a scheduled task [1]. That account is the Gunra tell. If you find one, treat the appliance as compromised and the broader network as at-risk: rotate Fortinet admin credentials, audit VPN concentrator logs for the access pattern that created the account, and patch CVE-2024-55591 and CVE-2025-24472 if you have not already.
- Audit your VDI authentication portal. AA26-222A documents Gunra actors modifying the VDI authentication portal to bypass MFA via a designated one-time password value [1]. If you run VDI, audit the portal source for changes, and audit VDI session cookies for unauthorized session hijacking.
- Check Hiware and similar physical-access control servers. AA26-222A documents the actors stealing a symmetric encryption key from a Hiware system access control server to decrypt stored credentials [1]. If you run Hiware or a similar physical access control system, audit logs for key extraction and consider rotating the symmetric key.
- Freeze your credit at all three bureaus. Equifax, Experian, TransUnion. A credit freeze is free, instant, and stops new-account fraud. Thaw it temporarily when you actually apply for credit.
- If Gunra hit your healthcare provider: watch your Explanation of Benefits for providers you never visited. Stolen medical identity is a longer-tail risk than credit-card fraud.
- File your taxes early. Stolen SSNs end up in fraudulent refund claims. The earlier you file, the less window a thief has to claim your refund.
- Switch to a hardware security key or passkey on every account that supports it. SIM swap attacks bypass SMS MFA, and phishing-resistant MFA stops the credential-access step of the Gunra playbook.
- Report to the FBI. AA26-222A's reporting channel list: FBI Internet Crime Complaint Center (ic3.gov), local FBI field office, the U.S. Secret Service local field office, or the CISA Incident Reporting System at 1-844-Say-CISA (1-844-729-2472) [1]. South Korean organizations can reach the Korean National Police Agency online cybercrime reporting system or 112 [1]. Send boundary logs showing foreign IP communications, ransom note samples, threat-actor communications, and any decryptor files if available.
If you are an IT or security lead at a company Gunra might target, the single highest-impact change is to patch every FortiOS and FortiProxy appliance on the AA26-222A CVE list and to audit for the presence of an unauthorized "forticloud-sync" super-user account. The second highest-impact change is to enforce phishing-resistant MFA on every admin portal and to audit your VDI authentication portal source for unauthorized modifications.
The Honest Takeaway
Gunra is what a 2026-era ransomware-as-a-service crew looks like when it gets a working strategy for expansion. CISA's advisory AA26-222A is the public accounting [1]. The FortiOS and FortiProxy authentication bypasses, the malicious "forticloud-sync" super-user account, the VDI authentication portal rewrite, and the Linux variant's PRNG weakness are the technical fingerprint. The Conti source-code lineage, the 80 percent affiliate cut, the dark web affiliate panel with a configurable builder, and the "Golden Community" alias are the commercial fingerprint. The HIPAA Journal leak-site tally of more than 30 victims and the Dragos Q2 2026 count of at least four industrial sector attacks are the scale fingerprint [2][3]. Acting CISA executive assistant director Chris Butera framed Gunra as part of an ongoing trend of ransomware attacks causing disruption and harm [3]. The American Hospital Association has alerted hospitals and health systems to be on guard [4].
What does not change is the playbook. Internet-facing Fortinet appliances that go unpatched. Super-user accounts created with hard-coded passwords via scheduled tasks. VDI authentication portals rewritten for MFA bypass. Symmetric keys extracted from physical access control servers. These are the front door, every time. The fix is procedural, not technical, and it has been on the CISA list since the first edition of AA26-222A.
This tracker will be updated as new victims are confirmed, additional indictments or sanctions land, and the international cases move forward.
Sources
- CISA, FBI, NSA, USSS, DC3, KNPA, #StopRansomware: Gunra Ransomware (AA26-222A, August 10, 2026)
- HIPAA Journal, Healthcare Orgs Warned About Gunra Ransomware Attacks (August 11, 2026)
- The Record, FBI, South Korea warn of Gunra ransomware gang (August 2026)
- American Hospital Association, Agencies warn of attacks by Gunra ransomware (August 11, 2026)
Published: October 7, 2026