Gunra ransomware: when the attacker owns your login page
A six-agency advisory details Gunra ransomware: Conti-derived, RaaS, double extortion. Its way in is vulnerabilities that have been on the KEV list since 2025.
Researched and drafted with AI assistance, then reviewed and edited by Shreyas Lipare before publication. Every source below was checked against the original.
There is a moment in the Gunra advisory that deserves to be read twice. At one victim, the actors did not defeat multi-factor authentication by phishing a code or stealing a token. They edited the authentication processing files on the company’s own login portal so that one specific one-time password value, a value they chose, would authenticate successfully, every time [1].
The login page still asked for a second factor. It still checked it. It just had a second correct answer that only the intruder knew.
That is the texture of this advisory. Gunra is not interesting because it is novel; it is interesting because it is thorough, and because the way in was a vulnerability that has been on a public list of known-exploited bugs since early 2025.
What happened
On August 10, 2026, six agencies published a joint advisory on Gunra ransomware, catalogued as AA26-222A: the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the US Secret Service, and the Republic of Korea’s National Police Agency [1].
Gunra first appeared in April 2025, derived from the Conti ransomware source code that leaked in 2022. It runs a double-extortion model: steal the data first, encrypt it second, and threaten to publish on a Tor leak site if nobody pays. Victims get a ransom note in every affected directory pointing to a negotiation portal, and five to seven days to make contact [1].
The change that matters happened in early 2026, when Gunra opened a formal ransomware-as-a-service affiliate program on dark web forums, a management panel, a configurable builder, cross-platform payloads, and documentation. The FBI notes the operation also adopted a second brand name, Golden Community, and that it actively recruits penetration testers to act as initial access brokers in exchange for a cut [1].
Victims listed on the leak site span the Americas, Europe, the Middle East, Africa and Asia-Pacific, across healthcare, financial services, manufacturing, transport, government, utilities, academia, media, retail and nonprofits [1]. That is not a targeting profile. That is an affiliate program taking whatever its affiliates can reach.
Why this matters
The headline finding is not the encryption. It is the front door.
The advisory names two vulnerabilities the FBI observed being used for initial access: CVE-2024-55591 and CVE-2025-24472, both authentication bypasses in FortiOS and FortiProxy [1]. Both are in CISA’s Known Exploited Vulnerabilities catalog. The first was added on January 14, 2025; the second on March 18, 2025. Both are flagged in the catalog as known to be used in ransomware campaigns [2].
So the position, as of August 2026, is this: a ransomware operation with a global affiliate program is getting into networks through authentication bypasses that were publicly documented as exploited, and flagged as ransomware-associated, roughly eighteen months ago.
For a leadership audience, that reframes the budget conversation. This is not a case for buying a new detection product. It is a case for finishing the patching you already know about on the devices facing the internet.
There is a second point worth carrying to a board. The advisory describes actors who deleted backup and archived data at both the primary data centre and the disaster recovery centre, before and after deploying the ransomware [1]. Disaster recovery that shares an identity plane with production is not disaster recovery. It is a second copy in the blast radius.
Technical breakdown
The sequence below is drawn from the advisory. Note that the FBI and the Korean National Police Agency contributed different observations from different victims. This is a composite of the tradecraft described, not a single intrusion.
- Initial accessExploits authentication bypass flaws in internet-facing firewall and VPN appliances that have been publicly listed as exploited since early 2025
BREAK THE CHAIN HERE
Patch CVE-2024-55591 and CVE-2025-24472 on FortiOS and FortiProxy, then clear the rest of your KEV backlog on anything with a public IP. Detection: alert on successful administrative authentication to an appliance from an address outside your admin ranges, and on configuration changes made outside a change window. - Credential accessAt one victim, signs in to an SSL-VPN administrative console using default credentials, on an account with no lockout policy
BREAK THE CHAIN HERE
Replace every vendor default credential on appliance admin consoles and enforce account lockout. Both halves matter, since lockout does not help when the password is printed in a manual. Detection: alert on repeated failed admin authentications, and on any successful login to an account that has never been used before. - PersistenceFinds a dormant account with both internet-facing and internal reach, and removes the forced password change so it can be used quietly
- Credential accessManipulates traffic handling on the VPN appliance to collect credentials and session data from users signing in to the internal desktop portal
- Defence evasionAlters authentication processing files on the portal so one attacker-chosen one-time password value always succeeds, defeating MFA on demand
BREAK THE CHAIN HERE
Run file integrity monitoring on authentication portal and VDI servers. Once an attacker can edit the code that decides whether a login succeeds, every identity control downstream is advisory, the only signal left is that the file changed. Detection: alert on any write to authentication handling files outside a deployment, and reconcile those paths against your build artefacts. - DiscoveryDumps password hashes from the domain controller and moves by remote desktop into Active Directory and IT staff workstations
- CollectionArchives business documents, databases and cloud content, then transfers it out to a file-sharing service
- ImpactDeletes volume shadow copies and destroys backups at both the primary and disaster recovery sites, then encrypts
Three of those steps carry a break marker, meaning a named control severs the chain there. Taking them in order:
Patching KEV-listed perimeter flaws removes the primary observed entry route. The advisory’s first recommended action is exactly this [1].
Removing default credentials and enforcing account lockout on appliance administrative consoles closes the second. The Korean National Police observed an administrator account reached through default credentials where no lockout control was present [1]. Both halves matter, lockout alone does not help if the password is published in a manual.
File integrity monitoring on authentication servers is what surfaces the third. Once an attacker can edit the code that decides whether a login succeeds, every downstream identity control is advisory. The only signal is that the file changed.
A few operational details are worth knowing because they shape detection.
Gunra actors work deliberately unsociable hours, the advisory records reconnaissance and internal activity concentrated between 10:00 p.m. and 6:00 a.m. [1]. They delete access logs and clear command history as they go [1]. For lateral movement they lean on Impacket’s SMB tooling and credential dumping against domain controllers, enabling pass-the-hash and pass-the-ticket onward movement [1].
The encryptor itself is self-contained and produces no network indicators, no
DNS, no HTTP, during encryption [1]. It skips system directories and
system-critical file extensions so it spends its time on user data, uses
multi-threaded ChaCha20 with RSA-4096, appends .ENCRT, and writes a ransom
note named R3ADM3.txt into each directory it finishes [1]. There is no
callback to catch. By the time the encryptor runs, detection has already failed.
The tools list is almost entirely legitimate software: 7-Zip, WinRAR, RClone, FileZilla, AnyDesk, Google Remote Desktop, MobaXterm, DBeaver, Visual Studio Code, Slack, Amass, Sliver, Mimikatz and Impacket [1]. CISA attaches an explicit caution that presence of these tools is not by itself evidence of compromise they are hunting leads, not verdicts.
What defenders should do Monday morning
Immediate: today.
Check your internet-facing Fortinet devices against CVE-2024-55591 and CVE-2025-24472 and patch anything outstanding [1][2]. Then widen that to every KEV-listed vulnerability on anything with a public IP. Separately, audit administrative accounts on VPN and firewall appliances for default credentials and for missing lockout policy. That is a same-day check, not a project.
Near term: this week.
Verify that at least one backup copy is offline or immutable and cannot be deleted using production domain credentials, and confirm this for the disaster recovery site as well as the primary [1]. Enable file integrity monitoring on authentication portal and VDI servers, so a change to authentication handling code raises an alert. Hunt for dormant and service accounts with both external and internal reach, and for accounts whose forced password change was recently cleared.
Structural: this quarter.
Segment the network so that a compromised workstation cannot reach domain controllers, backup infrastructure and NAS directly [1]. Move privileged administration to separate accounts with phishing-resistant authentication. Establish a baseline for out-of-hours administrative activity, so that reconnaissance between 10:00 p.m. and 6:00 a.m. is anomalous rather than invisible. Rehearse a restore, not a backup job report, an actual restore of a critical system from an offline copy, timed.
Checklist
- Patch CVE-2024-55591 and CVE-2025-24472 on FortiOS and FortiProxy, then clear the rest of your KEV backlog on internet-facing assets.
- Audit appliance admin consoles for default credentials and absent lockout.
- Confirm one backup copy is offline or immutable, at both primary and DR sites.
- Turn on file integrity monitoring for authentication and VDI portal servers.
- Find and disable dormant accounts that span external and internal networks.
- Alert on cleared event logs and cleared command history.
- Baseline overnight admin activity so 10:00 p.m. to 6:00 a.m. is reviewable.
- Segment backup infrastructure away from production domain credentials.
- Time an actual restore of one critical system this quarter.
The uncomfortable part
Strip out the specifics and Gunra is an ordinary intrusion. Unpatched edge device, default credentials, a forgotten account, credential dumping, lateral movement, backups deleted, files encrypted. Nothing in the chain requires a zero-day. The most sophisticated thing the actors did, backdooring the authentication logic so their chosen one-time password always worked, was possible only because they had already reached the server, and they reached it through a bug that had been on a public list for a year and a half.
That is the part worth sitting with. Six agencies co-authored a document about a global ransomware-as-a-service operation, and its first recommended action is to patch things you already know are being exploited. The advisory is not telling defenders something new. It is telling them the old thing still decides the outcome.
FREQUENTLY ASKED
- Is Gunra a new ransomware group?
- Not quite. The FBI first observed it in April 2025. What changed in early 2026 is the business model: it became a ransomware-as-a-service operation with an affiliate program, a management panel and a configurable builder, which means the people breaking into networks are now a much larger and more varied group than the people who wrote the malware.
- We have MFA on our VPN. Does that stop this?
- Not on its own. At one victim the actors modified the authentication processing files on the VDI portal so that one specific attacker-chosen one-time password value would always authenticate. That is a backdoor inside the authentication system itself, and no amount of MFA enrolment fixes it. File integrity monitoring on authentication servers is what catches it.
- What is the single highest-value thing to fix first?
- Patch internet-facing VPN and firewall appliances against vulnerabilities already on the CISA KEV list. The advisory names two Fortinet authentication bypasses as observed initial-access vectors, and both were added to KEV in early 2025. This is not a zero-day problem.
- Are our backups enough?
- Only if the attacker cannot reach them. At one victim, Gunra actors deleted backup and archived data at both the primary data centre and the disaster recovery centre, before and after deploying the ransomware. Backups that your domain admin can delete are backups the intruder can delete. Offline and immutable is the requirement.
- Does paying make the data go away?
- There is no evidence for that here, and the advisory describes actors who advertise victim datasets for sale on their leak site. The authoring agencies do not recommend paying. Treat exfiltrated data as disclosed and manage it as a breach notification problem, not a negotiation problem.
REFERENCES
BEFORE YOU GO
Was this useful?
Tell me what you'd change, what was unclear, or what you'd want covered next. Replies shape what gets written.
SEND FEEDBACK ↗