Understanding the Rise of Gunra Ransomware
In a collaborative effort between US and South Korean cybersecurity agencies, a warning was issued on August 10, 2026, regarding the sudden surge in Gunra ransomware attacks. Initially stemming from leaked Conti source code in early 2025, Gunra has evolved into a full-fledged Ransomware-as-a-Service operation. Offering affiliates a generous 80% share of ransom payments, Gunra has targeted critical infrastructure worldwide, posing threats to government services, transportation, healthcare, and banking sectors.
Insight into Gunra’s Tactics and Defensive Strategies
Gunra ransomware often exploits vulnerabilities such as CVE-2024-55591 and CVE-2025-24472 in FortiOS and FortiProxy, popular edge devices like firewalls and VPNs. Upon breaching systems, Gunra operatives swiftly cover their tracks by erasing command histories and event logs. They then utilize cloud services like Mega and OneDrive to store stolen data for exfiltration. Employing a double extortion technique, Gunra encrypts Windows and Linux machines and threatens to expose sensitive information unless a ransom is paid within a week. To enhance security measures, users are advised to regularly update software, enable multi-factor authentication, maintain offline backups, and stay vigilant against phishing scams.
Insights from the Author
The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and National Security Agency (NSA) jointly released an advisory titled “#StopRansomware: Gunra Ransomware” on August 10, 2026. For more information, visit cisa.gov/news-events/cybersecurity-advisories/aa26-222a.
Carmen Estela, a Cybersecurity Research Analyst at Cyber Defense Magazine, is a prominent figure in the industry. With a Master of Science degree from the University of Central Florida and a background in Criminology, she advocates for enhanced governance, risk, and compliance standards in cybersecurity. Carmen’s diverse experience in investigative roles across law enforcement and public service sectors contributes to her unique insights into emerging cyber trends.
Contact Carmen Estela at [email protected].

