What happened
On August 10, 2026, CISA, the FBI and international partners released a joint advisory on Gunra ransomware. Gunra first emerged in April 2025 as a double-extortion operation using a variant derived from leaked Conti source code. In January 2026, Gunra launched a formal ransomware-as-a-service programme and began recruiting affiliates and initial-access brokers. The advisory also records Golden Community as an operational alias used during this commercial expansion. Attribution posture: The joint CISA-FBI bulletin attributes the activity to Gunra ransomware actors and does not identify a government sponsor.
The agencies say Gunra affiliates encrypt systems, exfiltrate sensitive information and direct victims to a Tor-based negotiation portal. The advisory says victims are given five to seven days before threatened publication on Gunra’s dedicated leak site. The FBI observed attempts to contact management personnel directly by email to solicit payment. In one observed incident, Gunra actors deleted backup and archived data at both the primary data centre and the disaster-recovery centre, preventing restoration through those repositories.
Independent reporting says Gunra actors have targeted CVE-2024-55591 and CVE-2025-24472 in FortiOS and FortiProxy while also abusing exposed credentials and weak SSH controls on internet-facing VPN gateways. That combination means an organisation can complete patch deployment yet retain unresolved compromise risk from earlier access, stolen credentials or persistence. The CISA release bulletin did not publish hashes, filenames, IP addresses or domains for Gunra, so the immediate hunt must begin with exposure, authentication and privilege telemetry rather than an incomplete indicator-only search.
Why this matters now
The change is not that Gunra exists; the change is that multiple government partners have now assembled a decision-grade account of its affiliate model, access methods and recovery impact. A formal affiliate programme broadens the number of operators who may use the ransomware while making observed behaviour less uniform. Defenders therefore need controls that survive changes in payload, infrastructure and affiliate technique rather than detections tied only to a single binary.
The backup evidence deserves executive attention. Deletion across primary and disaster-recovery repositories indicates that nominal geographic or platform separation is insufficient when both environments share credentials, management planes or routable administrative paths. Recovery assurance must test whether an attacker controlling production identities can also disable retained copies, alter backup policies or reach the recovery environment.
Internet-facing remote access remains the decision point. VPN appliances and RDP services are privileged bridges into internal networks, yet ownership, patch state and logging are often split across infrastructure, network and security teams. Gunra’s observed use of both vulnerabilities and credentials means exposure management, identity containment and incident response must be assigned as one coordinated workstream.
The decision for security leaders
Direct the infrastructure and vulnerability teams to produce one reconciled inventory of public VPN and RDP exposure, including product owner, business dependency, applicable KEVs, fixed-state evidence and authentication-log location. Treat an unowned or unlogged service as an exception requiring an expiry date and accountable executive acceptance.
Require incident response to review the period preceding remediation on any affected remote-access appliance. Patch evidence closes the vulnerability task; it does not establish that credentials, sessions, configurations or downstream systems remained uncompromised before the update. Preserve appliance, identity-provider, firewall and endpoint evidence before routine retention removes it.
Make the continuity owner demonstrate restoration from an immutable copy using identities, networks and management systems isolated from production. The test should prove that a production-domain compromise cannot delete retained copies, change retention, obtain backup credentials or prevent the recovery team from accessing required documentation and tooling.
Evidence of closure
- An exposure register accounts for every externally reachable VPN and RDP service.
- Configuration evidence confirms applicable KEV remediation on each exposed gateway.
- Authentication review finds no unexplained successful sessions or documents their disposition.
- A clean-room restoration test succeeds without production identity infrastructure or network access dependency used for administration or recovery operations.
The Security.io assessment
The government advisory supports a high-confidence conclusion that Gunra is an active, commercially expanding ransomware operation with cross-sector reach. It does not establish that every affiliate uses the same access method, payload or infrastructure, and the release bulletin does not provide a compact indicator set. Behavioural and control-path hunts therefore carry more value than waiting for a definitive list of hashes or domains.
The most consequential evidence is the reported loss of backup and archived data in both primary and disaster-recovery locations. That is not proof that all Gunra incidents target recovery infrastructure, but it is sufficient to challenge any resilience design that relies on shared privileged identities or logical separation alone. Organisations unable to restore without production control planes should treat the gap as a current business-continuity risk.
Closure requires three separate findings: the exposed service is remediated, available evidence does not indicate earlier compromise, and recovery remains possible under hostile identity and network conditions. Combining those findings into a single patch-compliance percentage would conceal the decisions that security leadership needs to own.
Questions for the morning meeting
- Which remote-access systems remain exposed without complete ownership and telemetry?
- Can backup administrators authenticate if production identity services are unavailable?
- Who can authorise isolation of a critical VPN gateway during business hours?
- What evidence separates patched status from absence of earlier compromise?