On August 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Defense Cyber Crime Center (DC3), National Security Agency (NSA), U.S. Secret Service (USSS), and Republic of Korea’s National Police Agency (KNPA) released a joint advisory to alert organizations to the emerging Gunra ransomware threat and to provide detection and mitigation guidance.
This joint CSA is part of CISA’s ongoing #StopRansomware effort to provide defenders with intelligence and recommendations to help organizations identify, mitigate, and respond to ransomware activity.
Gunra is a ransomware strain that emerged in April 2025. Developed in C/C++ and reportedly derived from leaked Conti ransomware source code, Gunra has since been observed targeting organizations across multiple industries. In early 2026, the group expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program advertised on underground forums. The program provides affiliates with access to a management panel, configurable ransomware builders, cross-platform payloads, and supporting documentation. Gunra operates a double-extortion model in which sensitive data is exfiltrated before systems are encrypted, with victims threatened with publication of their stolen information through a dedicated data leak site. Ransom negotiations are conducted through a Tor-based portal.
According to the advisory, Gunra affiliates primarily gain initial access by exploiting vulnerabilities in internet-facing VPN and firewall infrastructure, including vulnerabilities affecting FortiOS and FortiProxy. The actors have also been observed abusing exposed credentials and SSH access-control weaknesses on VPN gateways. In one case, Gunra actors compromised an SSL-VPN appliance using default credentials and subsequently modified authentication processing on a corporate VDI portal to allow a specific attacker-controlled one-time password to bypass multifactor authentication. The actors have also manipulated VPN traffic-control functionality to intercept credentials and session information, using stolen session cookies to hijack legitimate user sessions and access internal environments.
Once inside the environment, Gunra actors perform lateral movement and credential theft using tools such as Impacket’s psexec.py, smbclient.py, and secretsdump.py. These tools are used to move between systems over SMB and dump credentials from compromised domain controllers, including extracting password hashes from the NTDS database. In another observed intrusion, the actors accessed a system access control server over SSH and obtained a symmetric encryption key that was used to decrypt stored enterprise credentials. To reduce visibility, Gunra actors have also been observed clearing command history and deleting system and network access logs.
Before deploying the ransomware, Gunra actors exfiltrate business-critical information, including documents, databases, personally identifiable information, and internal communications. The advisory describes the use of a custom executable named main.exe to collect data from Microsoft OneDrive and SharePoint, while large quantities of stolen data are compressed into archives and transferred to MEGA. Actors have also accessed VDI environments used by IT personnel to collect sensitive documents containing system and network configuration information. Following data theft, stolen enterprise credentials are used to deploy the ransomware across key assets, including database servers and network-attached storage systems. Gunra actors have additionally been observed deleting backup and archived data from both primary and disaster recovery infrastructure before and after ransomware deployment, further limiting the victim’s ability to recover affected systems.
To evaluate security controls against the behaviors observed in Gunra operations, AttackIQ recommends running the following emulation, which reproduces several of the adversary behaviors described in the advisory:
- [Malware Emulation] Gunra Ransomware – 2025-05 – Associated Tactics, Techniques and Procedures (TTPs)
Additionally, the following scenarios can be used to evaluate security control coverage against tools used by Gunra actors:
- Lateral Movement Through PAExec
- Dump Windows Passwords with Obfuscated Mimikatz
- Pass the Hash using Dumped Credentials
- Pass The Ticket
- Download 2025-04 Secretsdump Sample to Memory
- Save 2025-04 Secretsdump Sample to File System
Detection and Mitigation Opportunities
AttackIQ strongly recommends reviewing and following CISA’s recommendations, provided in the advisory to improve your organization’s cybersecurity posture on the basis of Gunra actor activity.
- Prioritize patching known exploited vulnerabilities [CPG 2.B] and the CVEs in this advisory in internet-facing systems—including VPN gateways and RDP-exposed infrastructure—and keep all OSs, software, and firmware up to date to support this.
- Implement a recovery plan to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (e.g., hard drive, storage device, the cloud) [CPG 3.I, 3.O, 1.C].
- Review domain controllers, servers, workstations, and active directories for new and/or unrecognized accounts [CPG 2.A, 2.E].
- Audit user accounts with administrative privileges and configure access controls according to the principle of least privilege [CPG 3.G].
- Segment networks [CPG 3.I] to prevent the spread of ransomware.
- Network segmentation can help prevent the spread of ransomware by controlling traffic flows between—and access to—various subnetworks and by restricting adversary lateral movement.
- Require MFA for all services to the extent possible, particularly for webmail, VPNs, and accounts that access critical systems [CPG 3.F].
- Disable command-line and scripting activities and permissions. Privilege escalation and lateral movement often depend on software utilities running from the command line. If threat actors are not able to run these tools, they will have difficulty escalating privileges and/or moving laterally [CPG 3.G, 3.M].
Wrap-up
In summary, these emulations, scenarios, and recommendations will help evaluate security and incident response processes and support the improvement of your security control posture against the behaviors exhibited by Gunra Ransomware. With data generated from continuous testing and use of these scenarios, you can focus your teams on achieving key security outcomes, adjust your security controls, and work to elevate your total security program effectiveness against a known and dangerous threat.
AttackIQ is the leader in threat-informed Continuous Threat Exposure Management (CTEM), helping organizations continuously validate defenses, optimize security controls, and reduce threat debt through evidence-based security operations. Through AVA Agentic OS, AttackIQ introduces the industry’s first agentic operating system for CTEM, enabling organizations to execute it autonomously at scale. By orchestrating specialized AI agents across threat intelligence, security validation, detection engineering, control optimization, threat debt reduction, and AI security validation, AttackIQ transforms fragmented security activities into continuous cyber resilience.
