Breaking: Gunra Ransomware Targets Critical Infrastructure — Joint CISA/FBI/NSA Advisory
Gunra Ransomware Targets Critical Infrastructure Across Europe and Asia — Joint CISA/FBI/NSA Advisory
A six-agency joint advisory published August 10 warns that Gunra ransomware is actively targeting healthcare, financial services, government facilities, and professional services organisations worldwide. Advisory AA26-222A, authored by CISA, FBI, NSA, US Secret Service, DoD Cyber Crime Center, and South Korea's National Police Agency, provides full tactical details on a ransomware-as-a-service operation that has listed 51 victims since April 2025, with the majority in Australia, East Asia, and Europe.
Gunra gains initial access by exploiting Fortinet FortiOS and FortiProxy vulnerabilities CVE-2024-55591 and CVE-2025-24472 in internet-facing devices. The operation then runs a double-extortion model: exfiltrate data, encrypt systems, and threaten publication on a Tor-based leak site if the ransom is not paid within five to seven days. The Conti-derived ransomware uses ChaCha20 or Salsa20 stream ciphers for encryption and has been observed encrypting 9TB in a single operation. A formal RaaS affiliate programme was launched on dark web forums in January 2026, offering affiliates a management panel, configurable builder, and cross-platform locker payloads.
The tradecraft is unusually sophisticated for a ransomware operation. Gunra actors have been observed tampering with VDI authentication portals to bypass MFA, inserting a hardcoded one-time password that grants access regardless of the real credential. They manipulate SSL-VPN appliance traffic control to intercept credentials and session cookies, then hijack sessions to impersonate legitimate users. Lateral movement uses Impacket's psexec.py and smbclient.py via SMB, with secretsdump.py harvesting password hashes from domain controllers. Data exfiltration routes through Microsoft OneDrive and SharePoint via an executable called main.exe, with select victims seeing terabyte-scale archives uploaded to MEGA. The group deletes system and network access logs, clears command history, and operates primarily between 10pm and 6am local time.
The Lazarus connection elevates concern. South Korean security researchers at AhnLab found that some of the watering-hole infrastructure used by Gunra also deployed Struggle (SIGNBT 3.0) and Brandoor (COPPERHEDGE), both attributed to North Korea's Lazarus Group. While Gunra and Lazarus appear to be separate operations, the shared infrastructure suggests limited collaboration or at least tool exchange. Palo Alto Networks previously documented Andariel, a Lazarus sub-cluster, partnering with Play ransomware in October 2024. The pattern of nation-state actors renting initial access to ransomware crews is accelerating.
For European organisations, the targeting pattern is clear. Spain features prominently in Gunra's victim list, and the operation's Fortinet-focused initial access vector overlaps significantly with the FortiBleed credential crisis, which compromised validated login credentials for 86,644 Fortinet firewalls across 194 countries. Any organisation still running unpatched FortiOS or using credentials that have not been rotated since June remains at elevated risk.
So What / Action
Three immediate actions. First, if you run Fortinet FortiGate or FortiProxy appliances, verify that CVE-2024-55591 and CVE-2025-24472 are patched and that all administrator credentials have been rotated, with MFA enforced and legacy SHA-256 password hashes eliminated. Second, hunt for Gunra indicators: Impacket tool execution on domain controllers, unexpected outbound connections to MEGA, authentication anomalies on SSL-VPN appliances, and any VDI authentication portal modifications that introduce static OTP values. Third, review backup architecture: Gunra deliberately deletes primary and disaster-recovery backups before encryption. If your backups are not immutable and physically segmented, they are not backups.
The joint advisory with full IOCs and detection guidance is at CISA AA26-222A.

