US Agencies Warn of Gunra Ransomware as Attackers Turn Firewall Flaws, Stolen Sessions and Backup Destruction Into a Full Enterprise Takeover + Video

Listen to this Post

Featured ImageA New Ransomware Threat Is Bigger Than Encryption

Ransomware has changed. The most dangerous attacks are no longer simply about locking files and demanding cryptocurrency. Modern ransomware crews increasingly behave like full-scale intrusion teams, spending days or weeks inside a victim’s network before triggering encryption at the most damaging moment.

That evolution is at the center of a new warning about Gunra ransomware, a threat that has reportedly developed from a ransomware strain into a more organized Ransomware-as-a-Service (RaaS) operation. The advisory described in the source was attributed to the FBI, CISA, NSA, U.S. Secret Service, DoD Cyber Crime Center and South Korea’s National Police Agency.

The warning is particularly significant because the reported Gunra attack chain stretches across almost every layer of a modern enterprise: internet-facing firewalls and VPN infrastructure, stolen credentials and sessions, authentication controls, lateral movement, cloud storage, backups and finally ransomware deployment.

The underlying message is uncomfortable but increasingly familiar: an organization can have strong endpoint protection and still be compromised if attackers first take control of the systems surrounding those endpoints.

Gunra’s Evolution From Ransomware to RaaS

According to the supplied advisory summary, Gunra first appeared in April 2025 and later developed into a more structured RaaS ecosystem during early 2026.

That transition matters because RaaS changes the economics of cybercrime.

Instead of a single group personally handling reconnaissance, initial access, privilege escalation, data theft, encryption and extortion, a RaaS model allows different criminals to specialize in different stages of an intrusion.

One actor may obtain access to a company.

Another may provide stolen credentials.

An affiliate may conduct the network intrusion.

A separate operator may handle the ransomware payload and negotiation.

The result is a criminal ecosystem that can scale far beyond what a small group of technically skilled attackers could accomplish alone.

The Shadow of Conti

One of the most important details in the report is Gunra’s reported connection to the leaked Conti ransomware source code.

Conti became one of the most influential ransomware families of the modern cybercrime era. Although the original Conti operation fractured, its technology, techniques, personnel and criminal infrastructure continued to influence subsequent ransomware operations.

A ransomware family derived from leaked or repurposed code does not necessarily mean the original Conti organization is behind it. Code can be copied, modified, reused and incorporated into entirely different criminal operations.

That distinction is important.

The more meaningful concern is that mature ransomware techniques can remain alive even after the original group disappears.

Gunra’s Most Dangerous Advantage May Be Initial Access

The encryption stage is often the part victims notice first.

It may actually be one of the least interesting parts of the intrusion.

The more important question is how attackers get inside.

The Gunra activity described in the advisory reportedly includes exploitation of internet-facing firewall and VPN infrastructure, including vulnerabilities CVE-2024-55591 and CVE-2025-24472 affecting FortiOS and FortiProxy.

Both vulnerabilities are particularly serious because they involve authentication bypass conditions, and both have appeared in CISA’s Known Exploited Vulnerabilities ecosystem.

NVD

+1

That makes externally exposed security appliances a particularly important defensive priority.

Why Firewall Vulnerabilities Are So Valuable

A vulnerable workstation may provide access to one employee.

A compromised edge device can potentially provide something much more valuable: a doorway into the organization itself.

Firewalls and VPN gateways sit at the boundary between the internet and internal infrastructure. They frequently handle authentication, remote access, network routing and security policies.

If attackers compromise that layer, they may not need to defeat every endpoint individually.

They can instead use the

CVE-2024-55591 Is Not a Theoretical Threat

CVE-2024-55591 is an authentication-bypass vulnerability affecting certain FortiOS and FortiProxy versions.

NIST’s National Vulnerability Database records the vulnerability as being included in CISA’s Known Exploited Vulnerabilities catalog. CISA’s assessment also identifies active exploitation and a potentially severe technical impact.

NVD

That history makes its appearance in a ransomware intrusion chain especially concerning.

Organizations should not treat old vulnerabilities as harmless simply because they were disclosed months or years ago.

A vulnerability can remain dangerous for years when vulnerable systems are forgotten, misconfigured or never properly removed from the internet.

CVE-2025-24472 Adds Another Entry Point

CVE-2025-24472 is another Fortinet authentication-bypass vulnerability affecting specified FortiOS and FortiProxy versions.

NIST records it as a CISA Known Exploited Vulnerability and documents active exploitation status in its vulnerability history.

NVD

The broader lesson is straightforward.

Internet-facing infrastructure must be patched according to exploitation risk, not merely according to how recently the vulnerability was disclosed.

Stolen VPN and VDI Sessions Can Defeat More Than Passwords

The Gunra activity described in the source reportedly goes beyond conventional credential theft.

Attackers have allegedly obtained VPN and VDI sessions and manipulated authentication mechanisms to bypass MFA protections.

This is an important distinction.

MFA is extremely valuable, but it is not a magical barrier against every attack.

If an attacker obtains an already authenticated session, steals session material, compromises an identity provider or takes control of an endpoint that has already completed MFA, the attacker may be able to operate with the victim’s existing trust.

This is why modern identity defense increasingly requires continuous verification rather than simply asking whether MFA was completed once.

The MFA Lesson Is Bigger Than Gunra

Organizations sometimes treat MFA as a checkbox:

MFA enabled = protected.

The reality is more complicated.

Security teams must also consider:

Session theft

Token theft

Device compromise

Privileged account abuse

Authentication-system manipulation

Legacy protocols

Excessive session lifetime

Weak conditional-access policies

Unusual login behavior

MFA remains one of the most important defenses available, but it works best as part of a layered identity-security strategy.

Impacket Gives Attackers a Powerful Toolkit

The reported Gunra activity includes legitimate penetration-testing and administration tools from the Impacket framework.

Among the tools mentioned are psexec.py, smbclient.py and secretsdump.py.

These tools can be extremely useful to legitimate security professionals.

The problem is that the same capabilities can be abused after an attacker gains sufficient access.

This reflects a broader trend known as living off the land or legitimate-tool abuse, where attackers rely on software already available within the environment instead of constantly introducing custom malware.

Why Legitimate Tools Make Detection Harder

Traditional antivirus defenses often focus heavily on malicious binaries.

But attackers do not always need a suspicious executable.

They may instead combine:

Legitimate administration utilities

Credential-dumping tools

Remote management software

File synchronization applications

Archive utilities

Cloud storage

Built-in operating-system functions

The resulting intrusion can look like normal IT activity until the individual actions are viewed together.

That is why behavioral detection and identity telemetry have become increasingly important.

Cloud Storage Becomes Part of the Extortion Pipeline

Another striking element of the Gunra activity described in the source is the reported theft of data from OneDrive and SharePoint.

Some incidents reportedly involved extremely large volumes of data, potentially reaching tens of terabytes.

This highlights a major problem for organizations that have successfully migrated their data to the cloud.

Moving information to the cloud does not eliminate ransomware risk.

It can change the target.

The Cloud Is Not Automatically a Backup

A cloud collaboration platform can contain enormous amounts of sensitive corporate information.

If an attacker compromises privileged accounts, they may potentially access:

Business documents

Contracts

Financial records

Customer information

Internal communications

Intellectual property

Project data

Executive files

The danger becomes greater when organizations confuse synchronized cloud storage with an independent backup strategy.

A synchronized file can still be deleted.

A compromised administrator can still modify data.

A cloud account can still be abused.

A resilient backup architecture therefore needs separation, immutability and independent recovery controls.

The Reported Toolset Shows a Multi-Stage Intrusion

The Gunra toolkit described in the source reportedly includes RClone, FileZilla, 7-Zip, WinRAR, Sliver, Mimikatz and AnyDesk, among other utilities.

The importance is not any individual tool.

It is the combination.

One tool may facilitate remote access.

Another may help steal credentials.

Another may move data.

Another may create archives.

Another may establish persistence or remote control.

Together, these tools can form a complete operational chain.

Data Theft Comes Before Encryption

The traditional ransomware image is simple: attackers encrypt files and display a ransom note.

Gunra reportedly follows the modern model.

First, attackers steal valuable information.

Then they encrypt systems.

Finally, they threaten to publish or sell the stolen data.

This is known as double extortion.

The strategy dramatically increases pressure on victims because restoring backups alone may no longer solve the problem.

Backup Destruction Is the Real Nightmare

The source describes incidents in which attackers allegedly deleted volume shadow copies and destroyed backup or archive data across both primary and disaster-recovery environments.

This is one of the most damaging developments in ransomware operations.

Organizations often assume:

“We have backups, so ransomware cannot stop us.”

But that assumption only holds if attackers cannot reach or manipulate those backups.

If attackers obtain sufficient administrative privileges, they may deliberately attack the recovery infrastructure before launching encryption.

Disaster Recovery Must Be Separated From Production

A backup system that shares the same administrative credentials, identity infrastructure and network access as production systems may be vulnerable to the same attacker.

That creates a dangerous chain:

Production compromise → administrator compromise → backup compromise → backup destruction → ransomware deployment.

The solution is not simply more backups.

The solution is independent recoverability.

Organizations should consider offline or logically isolated copies, immutable storage, separate administrative identities and regularly tested restoration procedures.

Gunra Reportedly Targets Windows and Linux

Another important aspect is

The source says both Windows and Linux ransomware variants have been observed.

That matters because Linux infrastructure increasingly sits at the heart of modern organizations.

Linux servers may host:

Databases

Virtualization infrastructure

Containers

Web applications

Storage systems

Development environments

Cloud workloads

Backup services

A ransomware operation capable of reaching both Windows and Linux environments can potentially create far more disruptive consequences.

The Linux Weakness Could Change the Outcome

Perhaps the most unusual technical detail is the reported weakness in certain Gunra Linux variants.

According to the supplied report, researchers identified a cryptographic implementation weakness that could allow encryption keys to be reconstructed using timing information such as file timestamps.

Independent security research describes a related Gunra Linux weakness involving time-seeded pseudo-random generation and reports that encrypted files may be recoverable without paying the attackers.

Breakglass Intelligence

That does not mean every Gunra-encrypted Linux system is automatically recoverable.

The weakness appears to depend on the specific Linux variant and implementation.

But it demonstrates an important reality of ransomware: attackers can build sophisticated operational infrastructure while simultaneously making mistakes in their cryptographic implementation.

ChaCha20 and RSA-4096 Sound Unbreakable — But Implementation Matters

The reported Windows variant uses ChaCha20 combined with RSA-4096.

Those algorithms are not inherently weak simply because ransomware uses them.

The real question is how keys are generated, protected and implemented.

Strong cryptography can be undermined by poor random-number generation, predictable seeds, key reuse, implementation errors or improper key management.

The Gunra Linux weakness is a useful reminder that cryptographic security depends on implementation, not just algorithm names.

The .ENCRT Extension Is Only the Visible Symptom

The reported Windows variant typically appends the .ENCRT extension to encrypted files.

For victims, this becomes one of the clearest signs that encryption has begun.

But by the time .ENCRT files appear across corporate systems, the attackers may already have completed the most important stages of their operation.

That is why detection must happen before encryption.

The real goal of modern ransomware defense is not to identify encrypted files quickly.

It is to identify the intrusion before attackers reach the encryption stage.

The Real Attack Chain Is Longer Than the Ransom Note

The Gunra activity can be understood as a sequence:

Internet-facing device exploitation → initial access → credential/session theft → authentication bypass → privileged access → lateral movement → data discovery → cloud exfiltration → backup destruction → encryption → extortion.

Every arrow represents an opportunity for defenders.

Stopping ransomware therefore does not require detecting the final payload.

Stopping any major stage of the attack can break the chain.

Why the RaaS Model Makes Gunra More Dangerous

Ransomware-as-a-Service creates specialization.

The people writing ransomware do not necessarily need to be the people breaking into networks.

That separation allows criminal organizations to scale.

It also creates a market for initial access brokers, credential sellers, malware developers, affiliates and negotiators.

The result is a cybercrime economy that resembles a distributed business.

Unfortunately, the infrastructure of legitimate digital businesses and criminal enterprises can sometimes look surprisingly similar.

What Undercode Says:

The Firewall Is Becoming the New Battlefield

The most important lesson from Gunra is that ransomware defense increasingly begins outside the endpoint.

Security teams should pay enormous attention to internet-facing appliances because these systems sit at the edge of the organization and frequently have privileged visibility into internal networks.

A vulnerable firewall can undermine layers of downstream security.

Patching Must Follow Exploitation Reality

CVE severity scores matter, but active exploitation matters even more.

Both CVE-2024-55591 and CVE-2025-24472 have documented exploitation-related significance, making them particularly important when assessing exposed Fortinet infrastructure.

NVD

+1

MFA Is Necessary but Not Sufficient

The reported use of stolen sessions and authentication bypass techniques demonstrates why organizations cannot stop their identity strategy at MFA enrollment.

Session security, conditional access and privileged identity controls are becoming equally important.

Identity Is the New Perimeter

Once attackers obtain a legitimate identity, many security controls begin treating them as trusted users.

That makes compromised credentials one of the most valuable commodities in the ransomware economy.

Privileged Accounts Deserve Special Attention

An ordinary account may provide limited access.

A privileged account can potentially unlock servers, cloud resources, backups and security systems.

Organizations should minimize administrative privileges and closely monitor privileged activity.

Backup Systems Are Strategic Targets

Attackers understand that backups reduce their leverage.

Consequently, destroying backups can be as strategically important as encrypting production data.

Immutable Backups Change the Equation

An immutable backup that attackers cannot modify or delete gives victims something extremely valuable: negotiating power.

It can transform a catastrophic ransomware incident into a difficult but manageable recovery operation.

Recovery Must Be Tested

A backup that has never been restored is an assumption, not a proven recovery mechanism.

Organizations should periodically perform realistic restoration exercises.

Cloud Data Needs Independent Protection

OneDrive and SharePoint can be extremely valuable business repositories.

But synchronization should not be confused with immutable backup.

Critical cloud information needs independent recovery strategies.

Data Exfiltration Can Be More Dangerous Than Encryption

Encryption disrupts operations.

Data theft can create years of consequences through regulatory exposure, intellectual-property loss, customer notification obligations and reputational damage.

Double Extortion Changes Incident Response

Incident response teams must now answer two questions:

Can we restore our systems?

And:

What information did the attackers steal?

Neither question can be ignored.

Large-Scale Exfiltration Leaves Signals

Moving terabytes of information is difficult to hide completely.

Security teams should monitor unusual outbound transfers, abnormal cloud downloads, archive creation and unexpected synchronization activity.

Legitimate Tools Can Become Attack Infrastructure

RClone, FileZilla, WinRAR, 7-Zip and remote-access utilities can all have legitimate uses.

The presence of such software is not automatically evidence of compromise.

Context matters.

Behavioral Detection Is Critical

The question should not simply be:

Is this tool malicious?

The better question is:

“Why is this account using this tool against these systems at this time?”

Lateral Movement Is a Major Detection Opportunity

An attacker moving from one machine to another generates patterns.

Unusual SMB activity, remote execution, credential access and privileged logins can provide valuable warning signs before encryption begins.

Network Segmentation Can Break the Chain

If attackers compromise one workstation but cannot freely reach servers, identity systems and backups, the potential blast radius becomes dramatically smaller.

Segmentation is therefore a ransomware control, not merely a network-design preference.

Backup Networks Should Not Be Ordinary Networks

Backup infrastructure deserves stronger isolation than typical corporate systems.

If an attacker can administer production and backups using the same credentials, the architecture may contain a dangerous single point of failure.

Linux Cannot Be Ignored

The reported Gunra Linux variant demonstrates why Linux systems should be included in ransomware preparedness exercises.

Organizations sometimes focus heavily on Windows endpoints while overlooking critical Linux servers.

Cross-Platform Ransomware Raises the Stakes

A ransomware family capable of operating across Windows and Linux environments can threaten a broader portion of the enterprise.

That is especially important for organizations with hybrid infrastructure.

Cryptographic Mistakes Can Save Victims

The reported Linux weakness is a reminder that attackers do not necessarily implement perfect encryption.

Security researchers should continue analyzing ransomware samples because weaknesses in key generation or encryption logic can sometimes provide recovery opportunities.

Victims Should Preserve Evidence

When ransomware strikes, immediately destroying infected machines can eliminate valuable forensic evidence.

Organizations should preserve logs, affected systems and relevant network telemetry whenever operationally possible.

Paying Is Not a Guaranteed Solution

Even when attackers provide a decryptor, victims cannot assume that every system or file will be successfully restored.

And paying does not erase stolen information that may already have been copied.

The Criminal Economy Is Becoming Modular

RaaS is powerful because it divides labor.

One criminal does not need to master every part of an attack.

That makes ransomware more scalable and resilient.

Initial Access Brokers Matter

The growing specialization of cybercrime means access itself has become a commodity.

A ransomware affiliate may purchase access rather than discover the vulnerability personally.

Old Vulnerabilities Can Become New Breaches

A vulnerability does not stop being dangerous because the security community has known about it for months.

Unpatched systems remain exploitable.

Exposure Matters as Much as Software Version

A vulnerable appliance hidden behind strong network controls is different from the same vulnerable appliance exposed directly to the internet.

Attack surface management therefore matters enormously.

Authentication Systems Must Be Hardened

If attackers can manipulate authentication mechanisms, bypass MFA or steal authenticated sessions, even otherwise strong passwords become less useful.

Identity infrastructure deserves the same defensive attention as endpoints.

Security Teams Need Attack-Path Thinking

Instead of asking whether individual controls are working, defenders should ask:

Can an attacker move from an exposed firewall to an administrator, from that administrator to backups, and from backups to every critical server?

That question exposes weaknesses much faster.

Gunra Shows Why Defense Must Be Layered

No single security technology can reliably stop modern ransomware.

Firewalls, MFA, EDR, segmentation, privileged-access management, monitoring and immutable backups must work together.

The Best Ransomware Defense Happens Before Encryption

Once files begin receiving ransomware extensions, defenders are already fighting the final stage.

The real victory is detecting the attacker during reconnaissance, credential theft or lateral movement.

Organizations Should Assume Edge Devices Will Be Targeted

Internet-facing infrastructure is simply too valuable to ignore.

Security teams should continuously inventory exposed appliances and verify that management interfaces are properly restricted.

Backups Should Be Treated as Crown Jewels

If backups are the

They should not share unnecessary trust relationships with ordinary production systems.

The Gunra Story Is Bigger Than Gunra

This is not merely a story about one ransomware family.

It reflects the direction of ransomware as a whole: more specialization, more credential theft, more cloud targeting, more backup destruction and more aggressive extortion.

The Attack Surface Keeps Expanding

Organizations now operate across offices, VPNs, cloud platforms, SaaS applications, remote desktops, containers, mobile devices and third-party services.

Every connection creates another potential path.

Security Strategy Must Follow the Attacker

The attackers are no longer simply looking for files to encrypt.

They are looking for identities, sessions, administrative privileges, cloud data and recovery infrastructure.

Defenders must therefore protect those same assets.

The Most Valuable Security Question

The most important question after reading about Gunra is not:

Do we have ransomware protection?

It is:

“If an attacker gets inside today, how far can they travel before we detect them?”

That question should drive the next security assessment.

Deep Analysis: Breaking Down the Gunra Attack Chain
Command 1 — Map the Internet-Facing Attack Surface

Security teams should inventory every publicly reachable firewall, VPN gateway, remote-access service and administrative interface.

Anything exposed to the internet should have a documented owner, supported software version and defined patching process.

Command 2 — Prioritize Known Exploited Vulnerabilities

CVE-2024-55591 and CVE-2025-24472 should receive immediate attention in environments where affected Fortinet products or versions remain exposed. NIST records both vulnerabilities as part of the actively exploited vulnerability landscape.

NVD

+1

Command 3 — Hunt for Suspicious Authentication Events

Look for unusual administrative accounts, unexpected authentication changes, abnormal VPN activity and authentication events inconsistent with normal employee behavior.

Command 4 — Investigate Session Theft

Security teams should examine suspicious VPN and VDI sessions, particularly when login locations, devices, timing or behavioral patterns do not match the legitimate user.

Command 5 — Audit Privileged Accounts

Every privileged account should have a clear owner and business justification.

Unused administrative accounts should not remain active indefinitely.

Command 6 — Monitor Lateral Movement

Investigate unusual SMB connections, remote execution, credential-dumping activity and unexpected administrative access between servers.

Command 7 — Monitor Cloud Exfiltration

Large or unusual OneDrive and SharePoint downloads should trigger investigation, particularly when combined with suspicious authentication activity.

Command 8 — Protect the Backup Layer

Ensure backup administrators, credentials and management interfaces are separated from ordinary production access wherever possible.

Command 9 — Test Recovery

Organizations should perform recovery exercises that simulate the loss of production systems and the compromise of normal administrative accounts.

Command 10 — Hunt Before the Ransom Note

The ultimate objective should be detecting the intrusion before attackers reach the encryption phase.

That is the point where ransomware defense becomes proactive rather than reactive.

✅ Gunra Has Been Reported as a Conti-Derived Ransomware Family

Independent security research describes Gunra as a Conti-derived RaaS operation and documents both Windows and Linux activity.

Breakglass Intelligence

✅ The Fortinet Vulnerabilities Are Real and Have Exploitation Significance

CVE-2024-55591 and CVE-2025-24472 are documented FortiOS/FortiProxy authentication-bypass vulnerabilities, and both are represented in CISA’s exploited-vulnerability ecosystem through NIST’s records.

NVD

+1

⚠️ The Exact Joint Advisory Claims Require Caution

The supplied article attributes the full Gunra warning to a joint advisory identified as AA26-222A, dated August 10, 2026. I could not independently retrieve that exact government advisory through the available indexed search results, so the specific agency attribution and every operational detail should be treated as based on the supplied source until the original advisory is directly verified.

Prediction

(-1) Gunra-Like Ransomware Operations Will Become More Dangerous

The ransomware threat is likely to continue moving away from simple encryption and toward complete enterprise compromise.

(-1) Edge Devices Will Remain a Prime Target

Firewalls, VPN gateways and remote-access infrastructure are likely to remain attractive because compromising them can provide attackers with privileged pathways into corporate environments.

(-1) Identity Attacks Will Increase

Stolen credentials, session tokens and authentication mechanisms will increasingly become central to ransomware operations as organizations strengthen traditional endpoint defenses.

(+1) Better Backup Isolation Can Dramatically Reduce Ransomware Impact

Organizations that maintain genuinely isolated, immutable and regularly tested backups will have a significantly stronger recovery position when ransomware reaches production.

(+1) Ransomware Weaknesses Will Continue Creating Recovery Opportunities

As researchers reverse-engineer new ransomware families, implementation mistakes may occasionally allow victims to recover encrypted data without paying attackers. The reported Gunra Linux weakness is a strong example of why continued malware research matters.

Breakglass Intelligence

(-1) The Biggest Risk Will Remain the Full Attack Chain

Gunra demonstrates why organizations cannot focus exclusively on ransomware executables. The more dangerous scenario is an attacker who quietly moves from an exposed edge device to identities, servers, cloud data and backups before launching encryption.

(+1) Detection Before Encryption Will Become the Critical Objective

The organizations best positioned against ransomware will increasingly be those capable of detecting unusual authentication, lateral movement and data-exfiltration behavior hours or days before the ransom note appears.

▶️ Related Video (66% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube