Today in Surveillance:

  • The Gunra ransomware tracker is live. A Conti-derived ransomware-as-a-service brand that the FBI first observed in April 2025 now lists more than 30 worldwide victims on its dark web leak site. The August 10, 2026 joint advisory AA26-222A from CISA, the FBI, NSA, USSS, DC3, and the Republic of Korea National Police Agency names healthcare, financial services, critical manufacturing, transportation, utilities, and seven other sectors as targets across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific [1][2][3][4].
  • The front door is the FortiOS authentication bypass. Gunra affiliates exploit CVE-2024-55591 and CVE-2025-24472 against unpatched FortiOS and FortiProxy appliances, then create a Fortinet super-user account named "forticloud-sync" with a hard-coded password via a scheduled task [1]. That account name is the Gunra tell on a compromised firewall.
  • The affiliate program hands intruders 80 percent of any ransom. The advisory documents a formal RaaS program launched on dark web forums in January 2026 with a configurable builder, cross-platform locker payloads, and a recruiting pipeline aimed at penetration testers. The operators keep 20 percent and operate under the alias "Golden Community" [1][2].
  • The Linux variant has a real recovery path. Researchers identified a weak PRNG seeded with the predictable system srand(time(NULL)) in the Gunra Linux ELF variants appended with .GNRA. The weakness allows key recovery using file timestamps and recovery of files without paying the ransom. The Windows .ENCRT variant does not have the same weakness [1][2][3].
  • Q2 2026 was a heavy industrial quarter for Gunra. Dragos data published through The Record reports at least four industrial sector attacks attributed to Gunra in Q2 2026, against a backdrop of 1,140 ransomware incidents affecting industrial organizations. Acting CISA executive assistant director Chris Butera framed Gunra as part of an ongoing trend of ransomware attacks causing disruption and harm [3].

What Gunra Actually Is

Gunra is a ransomware-as-a-service brand, not a single hacker. The developers run the leak site, the negotiation chat, and the payment infrastructure. Affiliates do the intrusions and split the proceeds. CISA's advisory AA26-222A places the first known activity in April 2025, when the FBI observed the ransomware and its leak site [1]. The encryptor is built from the Conti ransomware source code that leaked in 2022 [1][2]. That code leak gave every new entrant in the ransomware space a head start, and Gunra is built on it directly.

Two things made Gunra matter in 2026. First, the targeting pattern. The August 10, 2026 advisory lists healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services as the named sectors [1]. Healthcare is one of the named critical-infrastructure sectors, and the American Hospital Association carried an August 11, 2026 headline alert on Gunra [4]. Second, the affiliate model matured. The advisory documents that Gunra launched a formal RaaS affiliate program on dark web forums in January 2026, with a management panel, a configurable ransomware builder, cross-platform locker payloads, structured affiliate documentation, and a recruiting pipeline aimed at penetration testers and ethical hackers willing to serve as initial access brokers [1]. The affiliate cut is reported at 80 percent of any generated ransom, with the operators keeping 20 percent [2].

Gunra actors also adopted the alias "Golden Community" as part of the same RaaS expansion [1]. The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments, with limited success [3]. HIPAA Journal reports the dark web leak site currently lists more than 30 worldwide victims as of August 2026 [2]. The full tracker, with the leak-site tally, the Q2 2026 industrial numbers, and the technical fingerprint, is now live on State of Surveillance [5].

The Playbook: How Gunra Gets In And Holds You Hostage

The advisory AA26-222A documents the full technique chain in detail [1]. The core entry vectors and tradecraft:

  • Two FortiOS and FortiProxy authentication bypasses. Gunra affiliates exploit CVE-2024-55591 and CVE-2025-24472 against unpatched FortiOS and FortiProxy appliances [1]. Both are catalogued as CWE-288 authentication-bypass issues affecting access control. Once in, the actors create a Fortinet super-user account named "forticloud-sync" with a hard-coded password via a scheduled task, and use it for persistent administrative access [1]. KNPA separately reports Gunra actors exploit credential-exposure and SSH access control vulnerabilities in internet-facing VPN gateways [1].
  • Encrypted messaging and direct outreach. The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments, with limited success [3]. Negotiation also flows through qTox encrypted messaging and a Tor-based negotiation panel where victims are assigned a Client ID and an initial password [1]. The advisory puts the standard negotiation window at five to seven days [1]. HIPAA Journal reports victims are given between five and ten days to commence negotiations [2].
  • Credential dumping with Impacket and Mimikatz. Gunra actors use secretsdump.py (Impacket) for NTDS.dit credential dumping, then move laterally with pass-the-hash and pass-the-ticket [1]. Mimikatz is on the menu for obvious use. The advisory documents the actors stealing a symmetric encryption key from a Hiware system access control server to decrypt stored credentials [1].
  • VDI session hijacking and MFA bypass. Gunra actors stole VDI session cookies for session hijacking, then modified the VDI authentication portal to bypass MFA via a Gunra-designated one-time password value [1]. That is a notable break from the usual playbook, where MFA bypass comes from social-engineering the help desk. Here, the actors rewrote the authentication portal itself.
  • Living off the land. FileZilla, Amass, RClone, Sliver, 7-Zip, WinRAR, DBeaver, Slack, Microsoft Visual Studio Code, MobaXterm, AnyDesk, and Google Remote Desktop are on the CISA list of leveraged tools [1]. None of these are malware-only. They are the same legitimate admin and remote-management tools your IT team probably already uses.
  • Operational timing. Gunra conducts malicious activities and internal infrastructure reconnaissance during late-night and early-morning hours, defined as 10:00 p.m. through 06:00 a.m. local time [1]. The malware uses the IsDebuggerPresent API for anti-debugging and excludes C:\Windows, C:\Program Files, and C:\Program Files (x86) from encryption, so the victim machine can still boot after encryption [1].
  • Defense impairment and shadow-copy deletion. Volume shadow copies are deleted via WMI: cmd.exe invokes WMIC.exe against the shadowcopy object with a where clause selecting by the shadow copy identifier, then the delete verb runs [1]. Backup and archived data at primary and disaster recovery centers are deleted by the actors [1]. The two together kill the usual recovery path.
  • Exfiltration via Mega. Stolen data goes out to the Mega file-sharing service, with the actors exfiltrating up to tens of terabytes [1]. Data exfiltrated includes business-critical documents, databases, personally identifiable information, and internal email communications including from Microsoft OneDrive and SharePoint [1][2]. Two main.exe binaries are on the CISA hash list for OneDrive and SharePoint exfiltration [1].
  • Encryption. The encryptor uses ChaCha20 with RSA-4096 in a multi-threaded architecture that supports parallel encryption of multiple files simultaneously [1]. The Windows variant appends the .ENCRT extension; a July 2025 sample appended the .CRYPT extension [1]. The Linux ELF variant appends the .GNRA extension [1]. The ransom note is dropped as R3ADM3.txt in each affected directory [1][2]. The Tor-based panel gives each victim a Client ID and initial password for negotiation.
  • Initial ransom asks. The advisory documents that Gunra "generally started negotiations at arbitrarily high ransom amounts (over tens of millions in US dollars)" [1]. HIPAA Journal reports that ransom demands in individual disclosures have exceeded $10 million [2]. No individual ransom payment amounts are disclosed in AA26-222A [1].

The single biggest lesson from AA26-222A is also the most boring one. Patching internet-facing FortiOS and FortiProxy appliances against CVE-2024-55591 and CVE-2025-24472 kills the most reliable initial access paths. The advisory puts it near the top. The rest of the mitigations, segmented offline backups, phishing-resistant MFA, least privilege, EDR, restrict RDP, audit admin accounts, and disable command-line and scripting permissions where feasible, are the same list every CISA advisory writes. They are the same list because they are the things that work.

The Linux Recovery Path That Does Not Exist On Windows

As of March 2026, researchers identified a weakness in the Gunra ransomware Linux ELF variants appended with .GNRA: the encryption keys use a weak pseudorandom number generator (PRNG) seeded with the predictable system srand(time(NULL)) [1]. Researchers reported the weakness allows key recovery using file timestamps and recovery of files without paying the ransom [2][3]. This is a real defensive opportunity that does not apply to the Windows .ENCRT variant.

The practical read is direct. If your infrastructure runs Linux or ESXi and you have been hit by Gunra, do not assume the only options are paying the ransom or rebuilding from backups. File timestamps are not a secret. Researchers have shown the seed is recoverable and the decryption is recoverable from that seed. The advisory itself notes the weakness, and CISA acting executive assistant director Chris Butera's framing of Gunra as part of an ongoing trend of ransomware attacks causing disruption and harm is the policy backdrop for pushing the recovery path through FBI reporting channels [3]. The Windows variant does not have this weakness, and on Windows the usual playbook applies: do not pay if there is any other option, audit admin accounts, segment backups offline, and report to the FBI [1][2][3].

If You Are A Gunra Victim: The First 48 Hours

If you got a ransom note, a leak-site countdown, or a notification from a Gunra-hit vendor or partner, take the offered identity protection. Then add these steps:

  • Do not pay if there is any other option. CISA, the FBI, and partner agencies state that "payment does not guarantee victim files will be recovered" and that payment may encourage further targeting. The Linux variant's PRNG weakness gives victims hit on Linux/ESXi infrastructure a real recovery path that does not involve paying the ransom [1][2][3].
  • Audit your Fortinet appliances immediately. If you run FortiOS or FortiProxy, check whether you have an unrecognized super-user account named "forticloud-sync" with a hard-coded password via a scheduled task [1]. That account is the Gunra tell. If you find one, treat the appliance as compromised and the broader network as at-risk: rotate Fortinet admin credentials, audit VPN concentrator logs for the access pattern that created the account, and patch CVE-2024-55591 and CVE-2025-24472 if you have not already.
  • Audit your VDI authentication portal. AA26-222A documents Gunra actors modifying the VDI authentication portal to bypass MFA via a designated one-time password value [1]. If you run VDI, audit the portal source for changes, and audit VDI session cookies for unauthorized session hijacking.
  • Check Hiware and similar physical-access control servers. AA26-222A documents the actors stealing a symmetric encryption key from a Hiware system access control server to decrypt stored credentials [1]. If you run Hiware or a similar physical access control system, audit logs for key extraction and consider rotating the symmetric key.
  • Freeze your credit at all three bureaus. Equifax, Experian, TransUnion. A credit freeze is free, instant, and stops new-account fraud. Thaw it temporarily when you actually apply for credit.
  • If Gunra hit your healthcare provider: watch your Explanation of Benefits for providers you never visited. Stolen medical identity is a longer-tail risk than credit-card fraud.
  • File your taxes early. Stolen SSNs end up in fraudulent refund claims. The earlier you file, the less window a thief has to claim your refund.
  • Switch to a hardware security key or passkey on every account that supports it. SIM swap attacks bypass SMS MFA, and phishing-resistant MFA stops the credential-access step of the Gunra playbook.
  • Report to the FBI. AA26-222A's reporting channel list: FBI Internet Crime Complaint Center (ic3.gov), local FBI field office, the U.S. Secret Service local field office, or the CISA Incident Reporting System at 1-844-Say-CISA (1-844-729-2472) [1]. South Korean organizations can reach the Korean National Police Agency online cybercrime reporting system or 112 [1]. Send boundary logs showing foreign IP communications, ransom note samples, threat-actor communications, and any decryptor files if available.

If you are an IT or security lead at a company Gunra might target, the single highest-impact change is to patch every FortiOS and FortiProxy appliance on the AA26-222A CVE list and to audit for the presence of an unauthorized "forticloud-sync" super-user account. The second highest-impact change is to enforce phishing-resistant MFA on every admin portal and to audit your VDI authentication portal source for unauthorized modifications. The full sector-by-sector coverage, including the leak-site victim list, the Q2 2026 industrial counts, the technical fingerprint, and the staff training guidance, is on the tracker [5].

What to Watch This Week

The 80 percent affiliate cut and the next initial access broker. Gunra's formal RaaS program launched in January 2026 with a documented recruiting pipeline aimed at penetration testers and ethical hackers willing to serve as initial access brokers [1]. Watch for new postings on the dark web forums where Gunra operates under the "Golden Community" alias, and watch whether the next major Gunra-hit sector comes through a previously clean IAB path.

The Linux recovery path in production. The PRNG weakness is documented in AA26-222A and in subsequent researcher disclosures as of March 2026 [1][2][3]. Watch whether FBI and CISA publish a decryptor Linux build, and whether victims hit on Linux/ESXi infrastructure report recoveries through the ic3.gov channel.

The Q2 2026 industrial aftermath. Dragos data published through The Record reports at least four industrial sector attacks attributed to Gunra in Q2 2026, against a backdrop of 1,140 ransomware incidents affecting industrial organizations [3]. Dragos also reported a 12 percent increase in industrial ransomware incidents from Q1 to Q2 2026 [3]. Watch for the Q3 2026 industrial-sector numbers and whether Gunra names appear in the next set of disclosures.

The Tor-based leak site moves. The Datapub.news clearnet mirror operated from June through July 2025 [1]. The Tor DLS moved to a new .onion address by March 2026 and to another by July 2026 [1]. Watch for the next .onion move and whether the operators continue to use the "Golden Community" alias or pick up a new one.

Sources

  1. CISA, FBI, NSA, USSS, DC3, KNPA: #StopRansomware: Gunra Ransomware (AA26-222A, August 10, 2026). https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
  2. HIPAA Journal: Healthcare Orgs Warned About Gunra Ransomware Attacks (August 11, 2026). https://www.hipaajournal.com/gunra-ransomware/
  3. The Record: FBI, South Korea warn of Gunra ransomware gang (August 2026). https://therecord.media/ransomware-south-korea-fbi-gunra
  4. American Hospital Association: Agencies warn of attacks by Gunra ransomware (August 11, 2026). https://www.aha.org/news/headline/2026-08-11-agencies-warn-attacks-gunra-ransomware
  5. State of Surveillance: Gunra Ransomware 2026 Tracker, Every Victim, Every Method (October 7, 2026). /articles/corporate/gunra-ransomware-2026-tracker