Gunra is a financially motivated ransomware-as-a-service (RaaS) operation first observed in April 2025. Derived from leaked Conti source code, it evolved into a formal affiliate program in early 2026 and has also used the alias Golden Community. Affiliates receive ransomware payloads, a configurable builder, a management panel, and operational documentation, while the operation has recruited access brokers to obtain enterprise footholds.
Gunra conducts double-extortion attacks: affiliates steal sensitive business data, encrypt victim systems, and threaten publication or sale of stolen material if a ransom is not paid. It has targeted government, critical-infrastructure, healthcare, financial-services, manufacturing, transportation, utilities, and other organizations across multiple global regions. Both Windows and Linux variants are documented. The Windows encryptor uses ChaCha20 with RSA-4096; Linux builds support multithreaded and partial encryption, although some Linux versions contained a weak random-number-generation implementation that may permit recovery in certain cases.
Observed intrusions commonly begin with exploitation of known vulnerabilities in internet-facing firewall and VPN appliances, including FortiOS and FortiProxy authentication-bypass flaws. Gunra actors have established persistent privileged access, stolen credentials and VPN or VDI session material, bypassed multifactor authentication by modifying authentication processing, and moved laterally with SMB-based tooling, remote administration mechanisms, and SSH tunnels. They have conducted internal reconnaissance, collected data from enterprise collaboration services and other systems, transferred compressed archives to cloud-hosted file-sharing services, deleted logs and command histories, and removed backups and archived data at primary and disaster-recovery environments before or around ransomware deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Affiliates exploit known vulnerabilities in internet-facing devices, including Fortinet appliances (CVE-2024-55591 and CVE-2025-24472), then exfiltrate data before encrypting systems and threaten to publish stolen files... | CISA, along with federal and international partners, released a joint #StopRansomware advisory on Gunra, a ransomware-as-a-service (RaaS) operation. Gunra first appeared in April 2025 as a double-extortion variant derived from the leaked Conti source code and expanded to a formal affiliate program in early 2026, at times operating under the alias “Golden Community.”
Affiliates exploit known vulnerabilities in internet-facing devices, including Fortinet appliances (CVE-2024-55591 and CVE-2025-24472), then exfiltrate data before encrypting systems and threaten to publish stolen files... | CISA, along with federal and international partners, released a joint #StopRansomware advisory on Gunra, a ransomware-as-a-service (RaaS) operation. Gunra first appeared in April 2025 as a double-extortion variant derived from the leaked Conti source code and expanded to a formal affiliate program in early 2026, at times operating under the alias “Golden Community.”
Attacks deploying the ransomware have leveraged security flaws in internet-facing Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS and FortiProxy (CVE-2025-24472) appliances to obtain initial access. | Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. "Gunra first emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti1 ransomware source code."
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers used the stolen cookies for session hijacking and also leveraged the VDI access to beat the target organization's multifactor authentication protection.
Gaining access to an administrator account for an SSL-VPN appliance by exploiting default credentials
The actors favor VPN gateways, RDP-exposed infrastructure, and unpatched edge devices for initial access.
Gunra exploits company VPNs and firewalls that are supposed to keep hackers out. In many cases, Gunra's affiliates find companies that have not properly patched against vulnerabilities, and exploit the flaw to let themselves in as if they had a legitimate password.
The attackers used the stolen cookies for session hijacking and also leveraged the VDI access to beat the target organization's multifactor authentication protection.
Gaining access to an administrator account for an SSL-VPN appliance by exploiting default credentials
The actors favor VPN gateways, RDP-exposed infrastructure, and unpatched edge devices for initial access.
Gunra actors modified authentication processing files on the corporate VDI authentication portal server to allow successful authentication when a specific, Gunra-designated one time password (OTP) value was entered, thereby enabling the continuous bypass of multi-factor authentication (MFA).
The group also has a blossoming track record in living of the land (LOTL) techniques, having been observed sneaking under the radar, deleting system and network access logs, and clearing command histories.
The attackers used the stolen cookies for session hijacking and also leveraged the VDI access to beat the target organization's multifactor authentication protection.
Gaining access to an administrator account for an SSL-VPN appliance by exploiting default credentials
Gunra actors modified authentication processing files on the corporate VDI authentication portal server to allow successful authentication when a specific, Gunra-designated one time password (OTP) value was entered, thereby enabling the continuous bypass of multi-factor authentication (MFA).
This includes OS credential dumping and, in one case, compromising a Hiware access control server, stealing the encryption key, and decrypting passwords stored in the database.
used the traffic control functionality to collect credentials and session information for employees authenticating to a corporate virtual desktop infrastructure (VDI) portal.
The attackers used the stolen cookies for session hijacking and also leveraged the VDI access to beat the target organization's multifactor authentication protection.
Gunra actors modified authentication processing files on the corporate VDI authentication portal server to allow successful authentication when a specific, Gunra-designated one time password (OTP) value was entered, thereby enabling the continuous bypass of multi-factor authentication (MFA).
The threat group then regularly exploits Impacket libraries psexec.py and smbclient.py to move laterally across victim networks using the Server Message Block (SMB) protocol.
Once inside, attackers can secretly explore a network, copy sensitive data to their own servers...
then exfiltrate data before encrypting systems and threaten to publish stolen files on a dedicated leak site if victims do not pay.
The attackers also try to weaken recovery by deleting volume shadow copies. In at least one reported incident, they removed backup and archived data at both primary and disaster-recovery sites before and after ransomware deployment.
Once inside, attackers can secretly explore a network, copy sensitive data to their own servers, and then - in a final step - encrypt files, locking staff out of the data they need to do their job, and leave a ransom note named R3ADM3.txt
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware mentioned only as a comparison to attacks leveraging exposed remote-access infrastructure.
Ransomware referenced solely as a comparison case for conventional extortion infrastructure: Tor negotiation portals, qTox victim discussions, dedicated leak sites, and Mega-hosted exfiltrated data.
A ransomware operation that expanded into a formal ransomware-as-a-service program, providing affiliates with a management panel, builder, payloads, and documentation. Observed activity included exploitation of known vulnerabilities in internet-facing VPN and firewall devices and deletion of backups and archived data at primary and disaster-recovery sites.
A financially motivated ransomware operation that steals sensitive data, encrypts victim systems, and uses double-extortion by threatening to publish stolen data unless a ransom is paid. By early 2026 it had developed into a ransomware-as-a-service operation with affiliates. The content notes Linux and Windows variants, with the Linux variant reportedly generating weak encryption keys in some cases.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.