EXECUTIVE SUMMARY:
Gunra is a ransomware-as-a-service (RaaS) operation that has been associated with attacks against organizations across multiple sectors. Its affiliates use exposed remote-access infrastructure, compromised credentials, and vulnerable edge devices, including vulnerabilities such as CVE-2024-55591 and CVE-2025-24472, to gain initial access before conducting reconnaissance, stealing sensitive information, and deploying ransomware. The campaign follows a double-extortion model in which stolen data is used to pressure victims into paying a ransom.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Gunra is a ransomware-as-a-service (RaaS) operation that has been associated with attacks against organizations across multiple sectors. Its affiliates use exposed remote-access infrastructure, compromised credentials, and vulnerable edge devices, including vulnerabilities such as CVE-2024-55591 and CVE-2025-24472, to gain initial access before conducting reconnaissance, stealing sensitive information, and deploying ransomware. The campaign follows a double-extortion model in which stolen data is used to pressure victims into paying a ransom.[emaillocker id="1283"]
Gunra affiliates have exploited internet-facing VPN and firewall infrastructure, including vulnerabilities in FortiOS and FortiProxy, to obtain unauthorized access. Attackers have also abused default credentials, authentication weaknesses, stolen session information, and remote-access services to bypass security controls and move through victim environments. Following initial compromise, they may use tools such as Impacket, OpenSSH, Rclone, 7-Zip, and FileZilla for credential theft, lateral movement, tunneling, data collection, and exfiltration. The ransomware encrypts targeted files using ChaCha20 and RSA-4096 encryption, commonly appending the .ENCRT extension and dropping ransom notes. Attackers have additionally been observed deleting shadow copies and disrupting backup infrastructure to hinder recovery.
Gunra represents a significant ransomware threat because it combines RaaS-based operations, data exfiltration, file encryption, recovery inhibition, and extortion tactics. Its ability to operate across Windows and Linux environments broadens the potential attack surface and increases the risk to organizations with heterogeneous infrastructure. Organizations should prioritize strong access controls, phishing-resistant authentication, timely vulnerability remediation, endpoint monitoring, network segmentation, and offline or otherwise isolated backups. Security teams should also monitor for unusual file-encryption activity, shadow-copy deletion, unauthorized remote access, large-scale data transfers, and other behaviors associated with ransomware deployment to enable earlier detection and containment.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial Access | T1190 | Exploit Public-Facing Application | - |
| Execution | T1047 | Windows Management Instrumentation | - |
| T1106 | Native API | - | |
| T1059.003 | Command and Scripting Interpreter | Windows Command Shell | |
| Persistence | T1098.001 | Account Manipulation | Additional Cloud Credentials |
| T1133 | External Remote Services | - | |
| Privilege Escalation | T1078.001 | Valid Accounts | Default Accounts |
| T1078.002 | Domain Accounts | ||
| Stealth | T1622 | Debugger Evasion | - |
| T1070.003 | Indicator Removal | Clear Command History | |
| T1678 | Delay Execution | - | |
| T1679 | Selective Exclusion | - | |
| Defense Impairment | T1685.005 | Disable or Modify Tools | Clear Windows Event Logs |
| Credential Access | T1003.003 | OS Credential Dumping | NTDS |
| T1040 | Network Sniffing | - | |
| T1539 | Steal Web Session Cookie | - | |
| T1555.005 | Credentials from Password Stores | Password Managers | |
| T1556.006 | Modify Authentication Process | Multi-Factor Authentication | |
| Discovery | T1083 | File and Directory Discovery | - |
| T1049 | System Network Connections Discovery | - | |
| Lateral Movement | T1021.001 | Remote Services | Remote Desktop Protocol |
| T1021.002 | SMB/Windows Admin Shares | ||
| T1550.002 | Use Alternate Authentication Material | Pass the Hash | |
| T1550.003 | Pass the Ticket | ||
| Collection | T1560.001 | Archive Collected Data | Archive via Utility |
| T1005 | Data from Local System | - | |
| T1114.002 | Email Collection | Remote Email Collection | |
| Command and Control | T1105 | Ingress Tool Transfer | - |
| T1572 | Protocol Tunneling | - | |
| Exfiltration | T1567.002 | Exfiltration Over Web Service | Exfiltration to Cloud Storage |
| T1048.003 | Exfiltration Over Alternative Protocol | Exfiltration Over Unencrypted Non-C2 Protocol | |
| Impact | T1486 | Data Encrypted for Impact | - |
| T1657 | Financial Theft | - | |
| T1490 | Inhibit System Recovery | - |
REFERENCES:
The following reports contain further technical details:
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
[/emaillocker]