
01 · Overview
Gunra Ransomware, first seen in April 2025, is a double-extortion ransomware-as-a-service operation derived from the leaked Conti ransomware source code and also known by the alias Golden Community. Gunra Ransomware initially targeted Windows environments before a Linux ELF variant was introduced in mid-2025, and by January 2026 the operation had formalized a structured dark-web affiliate program complete with a management panel and a configurable ransomware builder. Gunra Ransomware affiliates target Fortinet FortiOS, Fortinet FortiProxy, SSL-VPN appliances, Virtual Desktop Infrastructure (VDI) authentication portals, Microsoft OneDrive, Microsoft SharePoint, Hiware system access control servers, domain controllers, database servers, and Network Attached Storage (NAS) systems across the United States, Canada, Brazil, Argentina, Spain, France, Germany, Italy, the United Arab Emirates, South Korea, Japan, China, Australia, and dozens of other countries spanning the Americas, Europe, the Middle East, Africa, and the Asia-Pacific. Targeted industries include healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services.
| CVE ID | Name | Affected Product | Zero-Day | CISA KEV |
|---|---|---|---|---|
CVE-2024-55591 | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Fortinet FortiOS | — | — |
CVE-2025-24472 | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Fortinet FortiOS and FortiProxy | — | — |
02 · Technical Breakdown
Gunra Ransomware is a double-extortion ransomware operation first observed in April 2025 and derived from the leaked Conti ransomware source code, initially deployed against Windows environments. In mid-2025 the operators introduced a Linux variant, extending Gunra Ransomware to cross-platform campaigns. As of January 2026, Gunra Ransomware expanded operations through a structured ransomware-as-a-service affiliate program advertised on dark web forums, providing affiliates with a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation. During this expansion the operation was also observed operating under the alias Golden Community.
Gunra Ransomware affiliates obtain initial access primarily by exploiting vulnerabilities in internet-facing security appliances. The authoring agencies attribute intrusions to exploitation of CVE-2024-55591 and CVE-2025-24472, authentication-bypass flaws in Fortinet FortiOS and FortiProxy that the operators leverage to create persistent super-user accounts on compromised appliances. The operators additionally abuse exposed credentials and weak SSH access controls on internet-facing VPN gateways to establish remote access.
Following intrusion, Gunra Ransomware affiliates operate a data-theft-first playbook, exfiltrating sensitive data prior to encryptor deployment. The Gunra Ransomware locker employs a hybrid encryption scheme combining ChaCha20 for high-speed file encryption with RSA-4096 key wrapping, capable of encrypting very large data volumes within a limited timeframe. Victims are directed to a Tor-based negotiation portal, and the actors threaten to publish exfiltrated data on a dedicated leak site if the ransom is not paid within a five-to-seven-day deadline. Individual incidents have reportedly involved exfiltration of tens of terabytes and ransom demands exceeding tens of millions of dollars.
Gunra Ransomware targeting spans multiple sectors across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific, including healthcare, financial services, government, manufacturing, transportation, utilities, and retail. Leak-site-listed victims of Gunra Ransomware are concentrated in South Korea, Brazil, Spain, Thailand, and Hong Kong, with only limited North American exposure reported to date.
03 · Mitigation
Apply vendor patches for CVE-2024-55591 and CVE-2025-24472 on all internet-facing FortiGate firewalls and FortiProxy appliances and treat both as KEV-priority items; until patched, restrict management interfaces to trusted management networks and disable HTTP/HTTPS administrative access from the internet.
Alert on creation of files with .ENCRT extensions, appearance of R3ADM3.txt files, high-volume file rename bursts, and companion .keystore file creation, and monitor for the file hashes and executables listed in the Indicators of Compromise section.
Rotate every factory-default credential on SSL-VPN and VPN gateway appliances, enforce account lockout thresholds on administrative accounts, disable or delete unused accounts in the administrative web console, and remove configuration options that permit bypass of mandatory password change requirements.
Deploy detection logic for the Impacket suite (psexec.py, smbclient.py, secretsdump.py) including named-pipe artifacts, service creation over SMB, and anomalous authentication against domain controllers, and alert on unexpected NTDS.dit or SYSTEM/SECURITY hive access.
Store symmetric encryption keys used by system access control platforms such as Hiware in hardware security modules or protected keystores rather than on the server file system, restrict SSH access to these servers to jump hosts only, and monitor for credential store access anomalies from virtual desktops.
Keep at least one copy of sensitive data in offline, immutable storage that is physically separate from the primary environment and the disaster recovery site, restrict backup infrastructure credentials to dedicated privileged access workstations, and regularly test full restoration to confirm recoverability without ransom payment.
04 · Adversary Tradecraft
.ENCRT extension.05 · Forensic Markers
| Type | Value |
|---|---|
| SHA256 | 75e5621756e9d19efeac2bcbb2ac4711fb85243c03b0a19c05b18e31a780691e, 25c8cb27947042de89d634b3e260e614e5b1425a89494fa4e4295bcabfa8ee48, 2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751, 834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1, 91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0, a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9 |
| SHA1 | BB79502D301BA77745B7DBC5DF4269FC7B074CDA |
| MD5 | E57b130718373f6ba9b37f39ca1d7e3d, 7DD26568049FAC1B87F676ECFAAC9BA0 |
| IPv4 | 23[.]239[.]119[.]2, 23[.]239[.]119[.]3, 23[.]239[.]119[.]4, 23[.]239[.]119[.]5, 23[.]239[.]119[.]6, 86[.]54[.]28[.]216, 103[.]125[.]234[.]14, 70[.]36[.]99[.]82, 211[.]21[.]210[.]181, 123[.]184[.]143[.]105, 182[.]204[.]21[.]240, 182[.]204[.]16[.]112, 123[.]244[.]187[.]144, 182[.]204[.]39[.]118, 67[.]43[.]53[.]10, 123[.]246[.]37[.]108, 91[.]201[.]66[.]146 |
| Domain | datapub[.]news |
| Emails | a00f105546345756[@]proton[.]me, 4569f6322bc3b22e9[@]proton[.]me, ilovemycubscout[@]gmail[.]com, 6449a3c1e612168526[@]proton[.]me |
| Filename | main.exe, cryptor.exe, msmp.exe, R3ADM3.txt |
| TOR Address | gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad[.]onion, lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd[.]onion, nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd[.]onion |
| Tox ID | 2507312EC10BB44ED9DAA04E3C5C27E8C13154649B1A02E73ACFAE1681EE0208D05133A8FB22, 0FE87CED0C611AE97E049C64288557F49E8271E91399E849328B078DA789A573031783235BEF, 47829AF1C943D4C296C910706923AS199BDA4995B076ED9A9016F7DEF161D445DF00F13E6900, 9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47 |
| Malicious Account | forticloud-sync |
06 · Further Reading
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.