A Joint Advisory With an International Signature
Government cybersecurity advisories usually carry one or two agency names. The Gunra advisory carries more, which is itself a signal of how seriously authorities are treating the threat. The joint advisory, published August 10, 2026 and reported in detail by Infosecurity Magazine, was co-authored by the FBI, CISA, other US government agencies, and South Korea’s National Police Agency (KNPA) — an international co-signature that reflects Gunra’s victim footprint spanning both US and South Korean organizations.
The advisory’s technical core names two specific Fortinet vulnerabilities Gunra is actively exploiting to gain initial access: CVE-2024-55591, a critical authentication bypass affecting FortiOS and FortiProxy that lets an attacker gain super-admin privileges via crafted requests to the Node.js websocket module, and CVE-2025-24472, a high-severity flaw allowing unauthenticated super-admin access through crafted CSF proxy requests. Both vulnerabilities predate 2026, meaning the exposure Gunra is exploiting is not a fresh zero-day — it’s unpatched legacy infrastructure that organizations should already have remediated.
From Single Strain to Commercial Operation in a Year
Gunra’s own history illustrates a pattern security researchers have flagged repeatedly in 2026: ransomware groups moving from individual criminal operations to structured commercial platforms faster than in prior years. Gunra was first observed in April 2025, and its code is built on the leaked Conti ransomware source code from 2022 — meaning its core encryption capability was assembled from a previous group’s compromised toolkit rather than developed from scratch. By early 2026, Gunra had launched a formal ransomware-as-a-service affiliate program, operating under aliases including “Golden Community” — transforming from a single criminal strain into an open commercial model in roughly sixteen months.
Gunra’s operational tactics show a group optimizing for stealth as much as speed. The advisory notes the group conducts reconnaissance and malicious activity specifically between 10:00 PM and 6:00 AM in the victim’s local time zone — timing designed to minimize the chance of detection by security teams during active monitoring hours. Once inside a network, Gunra employs multi-factor authentication bypass techniques, establishes SSH tunneling for persistent access, and deletes logs to cover its tracks. For data exfiltration, the group uses a malicious executable specifically built to pull data from Microsoft OneDrive and SharePoint, compressing it into archives — and has successfully removed “tens of terabytes” of victim data in some documented cases, according to the advisory’s technical findings. Ransom negotiations reportedly open at tens of millions of dollars, with victims typically given a five-to-seven-day response window before the group escalates pressure.
The double-extortion model underlying those demands is now the industry default rather than the exception: Gunra encrypts a victim’s systems while simultaneously threatening to publish the exfiltrated data if the ransom deadline passes, giving the group two independent points of leverage over any single victim. Additional technical reporting confirms Gunra’s exfiltration tool, a malicious executable named “main.exe,” transfers its compressed archives to the Mega file-sharing service after pulling data from OneDrive and SharePoint, and separately details that the group deletes Windows volume shadow copies via Windows Management Instrumentation and specifically targets backup and disaster-recovery data — removing a victim’s ability to simply restore from backup rather than negotiate. Gunra’s encryption itself uses ChaCha20 paired with RSA-4096, appending file extensions .ENCRT or .CRYPT to locked files, and the same reporting expands the advisory’s named target sectors to include insurance, transportation, utilities, academia, media, communications, retail, and nonprofit services alongside healthcare, financial services, government, and manufacturing.
Gunra Fits a Broader 2026 Ransomware Surge
Gunra isn’t an isolated spike — it’s surfacing inside a broader escalation in ransomware activity that industry threat researchers have tracked building throughout 2026, with weekly cyberattack and ransomware incident volumes both trending upward year-over-year according to multiple threat intelligence firms monitoring the space. The pattern that matters for defenders isn’t the precise count of incidents industry-wide; it’s that Gunra represents one visible node in a ransomware ecosystem where new groups are launching, commercializing, and scaling faster than the historical norm.
The advisory’s international authorship is itself worth reading closely. A CISA and FBI advisory that also carries South Korea’s National Police Agency as a named co-author signals that Gunra’s victim base already spans multiple continents seriously enough to justify a coordinated, cross-border law enforcement response rather than a purely domestic US alert — the kind of multi-agency signature that historically precedes either an active takedown operation or, at minimum, sustained cross-border intelligence sharing on the group’s infrastructure and affiliate identities.
Advertisement
What This Means for Security Teams Running Fortinet Infrastructure
1. Patch CVE-2024-55591 and CVE-2025-24472 immediately if not already done
Both vulnerabilities predate 2026 and have patches available; any organization still running unpatched FortiOS or FortiProxy instances vulnerable to these two CVEs should treat remediation as an emergency-priority action, not a routine patch cycle item, given confirmed active exploitation by a ransomware group with international law enforcement attention.
2. Extend monitoring coverage into off-hours windows specifically
Gunra’s documented pattern of operating between 10:00 PM and 6:00 AM local victim time means security teams relying primarily on business-hours monitoring staffing are structurally exposed to this group’s preferred operating window. Extend automated alerting sensitivity and, where feasible, human monitoring coverage into overnight hours, particularly for organizations in healthcare, financial services, government, and critical manufacturing — the four sectors the advisory specifically names as targeted.
3. Audit OneDrive and SharePoint exfiltration paths, not just endpoint defenses
Because Gunra’s confirmed exfiltration method specifically targets Microsoft OneDrive and SharePoint via a purpose-built executable, security teams should review data-loss-prevention coverage and anomalous-download alerting on these specific platforms rather than assuming general endpoint detection will catch the technique. Large, compressed-archive downloads from OneDrive/SharePoint outside normal business patterns should trigger immediate investigation.
The Bigger Pattern: Faster Commercialization, Same Old Vulnerabilities
What makes Gunra worth tracking beyond its own advisory isn’t novel technology — it’s the speed of its business-model maturation and the fact that it, like several rising 2026 ransomware operations, is finding its easiest entry through vulnerabilities that are a year or more old rather than fresh zero-days. A criminal operation going from first observation to a structured, branded affiliate program in roughly sixteen months, while exploiting patches that have been publicly available for months, is a case study in how much of the current ransomware surge is preventable through basic patch discipline rather than exotic defense. For organizations running Fortinet infrastructure in the sectors Gunra targets, the joint CISA-FBI-KNPA advisory isn’t a distant warning — it’s a specific, actionable patch list with a documented, currently-active threat actor attached to it.
Frequently Asked Questions
What vulnerabilities is Gunra ransomware exploiting?
Gunra is actively exploiting two Fortinet vulnerabilities: CVE-2024-55591, a critical authentication bypass in FortiOS/FortiProxy, and CVE-2025-24472, a high-severity flaw allowing unauthenticated super-admin access. Both were confirmed as actively exploited in the joint CISA-FBI-KNPA advisory published August 10, 2026.
Which sectors is Gunra targeting?
The joint advisory names healthcare, financial services, government organizations, and critical manufacturing as Gunra’s targeted sectors. The group operates a double-extortion model, encrypting data and threatening to publish stolen files unless a ransom is paid, with negotiations reportedly opening at tens of millions of dollars.
Is Gunra part of a wider ransomware trend in 2026?
Yes. Gunra is one of several ransomware operations that industry threat researchers have observed moving from initial detection to structured, affiliate-driven commercial operations within roughly a year — a faster commercialization timeline than seen in prior ransomware generations, according to the joint CISA-FBI-KNPA advisory’s own framing of the group’s evolution.
Sources & Further Reading
- #StopRansomware: Gunra Ransomware — CISA (Advisory AA26-222A)
- Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure — Infosecurity Magazine
- Gunra Ransomware Expands RaaS Operations, FBI Warns — The Cyber Express
- Feds Warn Gunra Ransomware Gang Is Targeting US Critical Infrastructure — Hoodline














