Security2 publishers3 min readPublished
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel
A six-agency #StopRansomware advisory dated August 10, 2026 gives defenders named CVEs, tooling and file extensions for a group that took about nine months to turn a variant into a business.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- A joint #StopRansomware advisory on Gunra ransomware was published August 10, 2026.
- The advisory was produced by CISA with the Department of Defense's Cyber Crime Center, FBI, National Security Agency, Secret Service and the Republic of Korea's National Police Agency.
- Counting the authoring bodies listed (CISA, DoD Cyber Crime Center, FBI, NSA, Secret Service, ROK National Police Agency) gives six agencies.
- The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant derived from leaked Conti ransomware source code.
- According to the agencies, Gunra is based on or influenced by the Conti ransomware code leaked in 2022.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Six government agencies published a joint #StopRansomware advisory on August 10, 2026 covering Gunra, a double-extortion ransomware variant the FBI first observed in April 2025 and which is derived from or influenced by the Conti source code leaked in 2022 [1][2][3][4][5]. The reason to care is not the strain itself but its business model: by January 2026 Gunra had launched a formal ransomware-as-a-service affiliate program advertised on dark web forums [6][7].
That is roughly nine months from first sighting to franchise [8]. Affiliates get a management panel, a configurable ransomware builder, cross-platform locker payloads and documentation [9]. The FBI also observed the group adopting new branding aliases, notably operating as Golden Community, and recruiting penetration testers and ethical hackers as initial access brokers in exchange for a share of ransom profits [10][11]. Gunra started on Windows, added a Linux variant, and has moved toward broader cross-platform targeting [12]. CyberScoop notes Gunra is not the only RaaS crew recruiting pentesters [13].
The entry points are unglamorous and patchable. Gunra actors primarily exploit known vulnerabilities in internet-facing firewalls and VPN gateways, and the FBI observed exploitation of CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in specific FortiOS and FortiProxy versions [14][15]. The Republic of Korea's National Police Agency separately observed credential exposure and SSH access control weaknesses on internet-facing VPN gateways [16]. In one case the actors compromised an SSL-VPN appliance using default credentials where account lockout was absent, then used stolen session information to reach internal virtual desktop infrastructure, Active Directory servers and IT personnel workstations [17]. Lateral movement used Impacket utilities over SMB [18].
Exfiltration comes first. The FBI observed collection of business-critical documents, databases, personally identifiable information and internal email [19]. In at least one case a malicious executable named main.exe pulled data from Microsoft OneDrive and SharePoint, and compressed archives went to Mega, with exfiltrated volume reaching tens of terabytes [20][21]. Encryption uses ChaCha20 and RSA-4096, with the .ENCRT extension observed and a July 2025 sample using .CRYPT [22][23]. Windows Management Instrumentation deletes volume shadow copies before encryption, and one victim had backup and archived data deleted from both primary and disaster recovery infrastructure [24][25].
Victims appear on the Tor leak site from Africa, the Americas, the Asia-Pacific, Europe and the Middle East, across healthcare, financial services and insurance, critical manufacturing, transportation, government, utilities, academia, media, retail and nonprofit services [26][27][28]. "Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations," said Chris Butera, CISA's acting assistant director for cybersecurity [29].
The attribution edge is thinner. Research published in July by AhnLab found overlap between Gunra and Lazarus Group without naming the latter, concluding the two appear to be separate actors with different objectives that may have shared techniques, tools and infrastructure or collaborated to a limited extent [30][31]. CyberScoop characterizes the alert as saying Gunra benefits from North Korean government-linked hackers' tools, and notes such collaboration dates back to at least 2024 [32][33].
What to watch: whether the Golden Community brand accumulates its own victim list separate from Gunra's, and whether the builder produces enough payload variation to break the .ENCRT and .CRYPT indicators. The advisory's own advice is dull and correct: patch known exploited vulnerabilities on VPN and RDP-exposed systems, keep offline immutable backups in segmented locations, segment networks, audit AD for unrecognized accounts and admin privileges, require MFA, and test controls against the mapped MITRE ATT&CK techniques [34][35][36][37].