Gunra is a financially motivated ransomware-as-a-service (RaaS) operation first observed in April 2025. Also known as Golden Community, it operates a double-extortion model: affiliates steal sensitive data, encrypt victim systems, and threaten to publish or sell stolen material through a leak site if ransoms are not paid. Gunra initially appeared to be derived from leaked Conti ransomware source code, expanded from Windows-focused activity to Linux payloads, and established a structured affiliate program in early 2026 that provides affiliates with ransomware builders, management infrastructure, cross-platform payloads, and operational documentation. Gunra primarily gains access by exploiting known vulnerabilities and weak controls in internet-facing VPNs, firewalls, and other edge appliances, including Fortinet FortiOS and FortiProxy vulnerabilities CVE-2024-55591 and CVE-2025-24472. Observed operations include abuse of default or exposed credentials, MFA bypass through modification of VDI authentication processing, theft of VPN credentials and session cookies, session hijacking, credential dumping, and privileged-account abuse. Actors have established persistence, used SSH tunneling, moved laterally over SMB with Impacket tooling, collected data from enterprise systems including Microsoft 365 services, compressed and exfiltrated large data volumes, deleted logs and command histories, and encrypted servers, databases, network-attached storage, and other business-critical assets. Gunra has also deleted backups at primary and disaster-recovery environments in observed intrusions. Gunra has targeted organizations worldwide, particularly government and critical-infrastructure entities, as well as healthcare, financial services, manufacturing, transportation, utilities, retail, professional services, and nonprofit organizations. Confirmed and reported victim activity includes organizations in South Korea, Brazil, Spain, Thailand, Hong Kong, the United States, Canada, Uruguay, Venezuela, Honduras, and Japan. The group recruits penetration testers and other access brokers in exchange for a share of ransom proceeds. Some reporting has identified overlap between Gunra tradecraft or infrastructure and activity associated with North Korean government-linked actors, including Lazarus Group-related tooling; Gunra itself has not been conclusively attributed to a state or country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The attacks hinge around two Fortinet vulnerabilities, CVE-2024-55591 and CVE-2025-24472, which exploit scheduled tasks on compromised FortiOS firewall devices to forge a new, malicious persistent user with super user privileges and a hard-coded password.
The attacks hinge around two Fortinet vulnerabilities, CVE-2024-55591 and CVE-2025-24472, which exploit scheduled tasks on compromised FortiOS firewall devices to forge a new, malicious persistent user with super user privileges and a hard-coded password.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation using data exfiltration, encryption, leak-site publication, victim-data previews, and a Tor-based negotiation portal.
Conducted a ransomware attack against Occidental, an organization in Venezuela.
Conducting a ransomware attack against Blanco & Etcheverry, a law firm in Uruguay.
Financially motivated ransomware-as-a-service operation conducting double-extortion attacks: stealing sensitive data, encrypting victim systems, and threatening publication unless a ransom is paid.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.