Gunra is a ransomware-as-a-service operation first observed in April 2025 and assessed to be derived from leaked Conti source code. It evolved from an initially Windows-focused ransomware into a cross-platform operation with a Linux variant and a formal affiliate program by early 2026, at times using the alias Golden Community. Gunra employs a double-extortion model in which affiliates exfiltrate data before encrypting systems and then threaten to publish stolen information on a dedicated leak site if payment is not made.
Gunra has targeted government, critical infrastructure, healthcare, financial services, manufacturing, transportation, utilities, academia, media, retail, nonprofit, and other enterprise environments across multiple world regions. Reported intrusions show a preference for exploiting known vulnerabilities in internet-facing edge infrastructure, especially Fortinet appliances affected by CVE-2024-55591 and CVE-2025-24472, as well as exposed VPN and RDP pathways. In some cases, operators have abused weak administrative controls, harvested credentials and session material from SSL-VPN and VDI environments, hijacked sessions, and tampered with authentication logic to bypass multifactor authentication and preserve access.
Post-compromise activity includes persistence through privileged account manipulation, credential theft, lateral movement over SMB and remote administration channels, internal reconnaissance, log clearing, and other defense-evasion measures. Gunra operators have been observed using common administrative and open-source tooling for movement and data theft, including utilities for credential dumping, remote execution, tunneling, archiving, and bulk transfer from enterprise cloud storage and collaboration platforms. Stolen data has included documents, databases, internal communications, and other sensitive business information, sometimes at very large scale. Gunra has also been observed deleting shadow copies, backups, and archived data to increase recovery difficulty.
The Windows encryptor has been reported to use ChaCha20 with RSA-4096 and to process files in parallel, while the Linux variant supports multithreaded and partial encryption. Researchers have also reported a weakness in the Linux variant’s random number generation that may enable key reconstruction and file recovery in some cases. Gunra is regarded as a significant enterprise ransomware threat because it combines opportunistic exploitation of exposed infrastructure, credential and session abuse, cross-platform encryption capability, and mature double-extortion tradecraft through an affiliate-driven operating model.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Affiliates exploit known vulnerabilities in internet-facing devices, including Fortinet appliances (CVE-2024-55591 and CVE-2025-24472), then exfiltrate data before encrypting systems and threaten to publish stolen files... | CISA, along with federal and international partners, released a joint #StopRansomware advisory on Gunra, a ransomware-as-a-service (RaaS) operation. Gunra first appeared in April 2025 as a double-extortion variant derived from the leaked Conti source code and expanded to a formal affiliate program in early 2026, at times operating under the alias “Golden Community.”
Affiliates exploit known vulnerabilities in internet-facing devices, including Fortinet appliances (CVE-2024-55591 and CVE-2025-24472), then exfiltrate data before encrypting systems and threaten to publish stolen files... | CISA, along with federal and international partners, released a joint #StopRansomware advisory on Gunra, a ransomware-as-a-service (RaaS) operation. Gunra first appeared in April 2025 as a double-extortion variant derived from the leaked Conti source code and expanded to a formal affiliate program in early 2026, at times operating under the alias “Golden Community.”
Attacks deploying the ransomware have leveraged security flaws in internet-facing Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS and FortiProxy (CVE-2025-24472) appliances to obtain initial access. | Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. "Gunra first emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti1 ransomware source code."
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers used the stolen cookies for session hijacking and also leveraged the VDI access to beat the target organization's multifactor authentication protection.
Gaining access to an administrator account for an SSL-VPN appliance by exploiting default credentials
The attackers used the stolen cookies for session hijacking and also leveraged the VDI access to beat the target organization's multifactor authentication protection.
Gaining access to an administrator account for an SSL-VPN appliance by exploiting default credentials
The actors favor VPN gateways, RDP-exposed infrastructure, and unpatched edge devices for initial access.
Gunra actors modified authentication processing files on the corporate VDI authentication portal server to allow successful authentication when a specific, Gunra-designated one time password (OTP) value was entered, thereby enabling the continuous bypass of multi-factor authentication (MFA).
The group also has a blossoming track record in living of the land (LOTL) techniques, having been observed sneaking under the radar, deleting system and network access logs, and clearing command histories.
The group also has a blossoming track record in living of the land (LOTL) techniques, having been observed sneaking under the radar, deleting system and network access logs, and clearing command histories.
The attackers used the stolen cookies for session hijacking and also leveraged the VDI access to beat the target organization's multifactor authentication protection.
Gaining access to an administrator account for an SSL-VPN appliance by exploiting default credentials
Gunra actors modified authentication processing files on the corporate VDI authentication portal server to allow successful authentication when a specific, Gunra-designated one time password (OTP) value was entered, thereby enabling the continuous bypass of multi-factor authentication (MFA).
This includes OS credential dumping and, in one case, compromising a Hiware access control server, stealing the encryption key, and decrypting passwords stored in the database.
used the traffic control functionality to collect credentials and session information for employees authenticating to a corporate virtual desktop infrastructure (VDI) portal.
The attackers used the stolen cookies for session hijacking and also leveraged the VDI access to beat the target organization's multifactor authentication protection.
Gunra actors modified authentication processing files on the corporate VDI authentication portal server to allow successful authentication when a specific, Gunra-designated one time password (OTP) value was entered, thereby enabling the continuous bypass of multi-factor authentication (MFA).
The threat group then regularly exploits Impacket libraries psexec.py and smbclient.py to move laterally across victim networks using the Server Message Block (SMB) protocol.
The threat group then regularly exploits Impacket libraries psexec.py and smbclient.py to move laterally across victim networks using the Server Message Block (SMB) protocol.
The attackers also try to weaken recovery by deleting volume shadow copies. In at least one reported incident, they removed backup and archived data at both primary and disaster-recovery sites before and after ransomware deployment.
the ransomware they deploy appends a .encrt extension to encrypted files and drops a ransom note named r3adm3.txt in multiple directories
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation using double extortion: affiliates exploit known vulnerabilities in internet-facing devices, exfiltrate data, encrypt systems, and threaten to publish stolen files on a dedicated leak site if victims do not pay. The Linux variant reportedly uses a weak time-seeded random number generator that may allow key reconstruction and file recovery.
Enterprise-focused ransomware that compromises exposed edge devices, steals large volumes of data, and encrypts Windows and Linux systems using double extortion. The operation uses stolen sessions, RDP, Impacket over SMB, OpenSSH tunnels, data theft from OneDrive and SharePoint, and attempts to impair recovery by deleting shadow copies and removing backup data.
Gunra is a ransomware family operated as a ransomware-as-a-service platform. It uses double extortion by encrypting victim data and exfiltrating it, then threatening publication on a dedicated leak site if the ransom is not paid.
Referenced only in a related-articles link as a ransomware family targeting government agencies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.