Threat Advisory

Gunra Ransomware Encrypts Systems and Exfiltrates Government Data

Threat: Ransomware
Targeted Region: Global
Targeted Sector: Technology & IT, Education, Finance & Banking, Critical Infrastructure, Entertainment & Telecommunication, Retail & E-commerce, Healthcare, Government & Defense
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Gunra is a ransomware-as-a-service (RaaS) operation that has been associated with attacks against organizations across multiple sectors. Its affiliates use exposed remote-access infrastructure, compromised credentials, and vulnerable edge devices, including vulnerabilities such as CVE-2024-55591 and CVE-2025-24472, to gain initial access before conducting reconnaissance, stealing sensitive information, and deploying ransomware. The campaign follows a double-extortion model in which stolen data is used to pressure victims into paying a ransom.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Gunra is a ransomware-as-a-service (RaaS) operation that has been associated with attacks against organizations across multiple sectors. Its affiliates use exposed remote-access infrastructure, compromised credentials, and vulnerable edge devices, including vulnerabilities such as CVE-2024-55591 and CVE-2025-24472, to gain initial access before conducting reconnaissance, stealing sensitive information, and deploying ransomware. The campaign follows a double-extortion model in which stolen data is used to pressure victims into paying a ransom.[emaillocker id="1283"]

Gunra affiliates have exploited internet-facing VPN and firewall infrastructure, including vulnerabilities in FortiOS and FortiProxy, to obtain unauthorized access. Attackers have also abused default credentials, authentication weaknesses, stolen session information, and remote-access services to bypass security controls and move through victim environments. Following initial compromise, they may use tools such as Impacket, OpenSSH, Rclone, 7-Zip, and FileZilla for credential theft, lateral movement, tunneling, data collection, and exfiltration. The ransomware encrypts targeted files using ChaCha20 and RSA-4096 encryption, commonly appending the .ENCRT extension and dropping ransom notes. Attackers have additionally been observed deleting shadow copies and disrupting backup infrastructure to hinder recovery.

Gunra represents a significant ransomware threat because it combines RaaS-based operations, data exfiltration, file encryption, recovery inhibition, and extortion tactics. Its ability to operate across Windows and Linux environments broadens the potential attack surface and increases the risk to organizations with heterogeneous infrastructure. Organizations should prioritize strong access controls, phishing-resistant authentication, timely vulnerability remediation, endpoint monitoring, network segmentation, and offline or otherwise isolated backups. Security teams should also monitor for unusual file-encryption activity, shadow-copy deletion, unauthorized remote access, large-scale data transfers, and other behaviors associated with ransomware deployment to enable earlier detection and containment.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial Access T1190 Exploit Public-Facing Application -
Execution T1047 Windows Management Instrumentation -
T1106 Native API -
T1059.003 Command and Scripting Interpreter Windows Command Shell
Persistence T1098.001 Account Manipulation Additional Cloud Credentials
T1133 External Remote Services -
Privilege Escalation T1078.001 Valid Accounts Default Accounts
T1078.002 Domain Accounts
Stealth T1622 Debugger Evasion -
T1070.003 Indicator Removal Clear Command History
T1678 Delay Execution -
T1679 Selective Exclusion -
Defense Impairment T1685.005 Disable or Modify Tools Clear Windows Event Logs
Credential Access T1003.003 OS Credential Dumping NTDS
T1040 Network Sniffing -
T1539 Steal Web Session Cookie -
T1555.005 Credentials from Password Stores Password Managers
T1556.006 Modify Authentication Process Multi-Factor Authentication
Discovery T1083 File and Directory Discovery -
T1049 System Network Connections Discovery -
Lateral Movement T1021.001 Remote Services Remote Desktop Protocol
T1021.002 SMB/Windows Admin Shares
T1550.002 Use Alternate Authentication Material Pass the Hash
T1550.003 Pass the Ticket
Collection T1560.001 Archive Collected Data Archive via Utility
T1005 Data from Local System -
T1114.002 Email Collection Remote Email Collection
Command and Control T1105 Ingress Tool Transfer -
T1572 Protocol Tunneling -
Exfiltration T1567.002 Exfiltration Over Web Service Exfiltration to Cloud Storage
T1048.003 Exfiltration Over Alternative Protocol Exfiltration Over Unencrypted Non-C2 Protocol
Impact T1486 Data Encrypted for Impact -
T1657 Financial Theft -
T1490 Inhibit System Recovery -

 

REFERENCES:

The following reports contain further technical details:

https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a

[/emaillocker]
crossmenu