Security2 distinct publishers3 min readUpdated
A six-agency #StopRansomware advisory dated August 10, 2026 gives defenders named CVEs, tooling and file extensions for a group that took about nine months to turn a variant into a business.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
A six-agency #StopRansomware advisory dated August 10, 2026 gives defenders named CVEs, tooling and file extensions for a group that took about nine months to turn a variant into a business.
Six government agencies published a joint #StopRansomware advisory on August 10, 2026 covering Gunra, a double-extortion ransomware variant the FBI first observed in April 2025 and which is derived from or influenced by the Conti source code leaked in 2022 [1][2][3][4][5]. The reason to care is not the strain itself but its business model: by January 2026 Gunra had launched a formal ransomware-as-a-service affiliate program advertised on dark web forums [6][7].
That is roughly nine months from first sighting to franchise [8]. Affiliates get a management panel, a configurable ransomware builder, cross-platform locker payloads and documentation [9]. The FBI also observed the group adopting new branding aliases, notably operating as Golden Community, and recruiting penetration testers and ethical hackers as initial access brokers in exchange for a share of ransom profits [10][11]. Gunra started on Windows, added a Linux variant, and has moved toward broader cross-platform targeting [12]. CyberScoop notes Gunra is not the only RaaS crew recruiting pentesters [13].
The entry points are unglamorous and patchable. Gunra actors primarily exploit known vulnerabilities in internet-facing firewalls and VPN gateways, and the FBI observed exploitation of CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in specific FortiOS and FortiProxy versions [14][15]. The Republic of Korea's National Police Agency separately observed credential exposure and SSH access control weaknesses on internet-facing VPN gateways [16]. In one case the actors compromised an SSL-VPN appliance using default credentials where account lockout was absent, then used stolen session information to reach internal virtual desktop infrastructure, Active Directory servers and IT personnel workstations [17]. Lateral movement used Impacket utilities over SMB [18].
Exfiltration comes first. The FBI observed collection of business-critical documents, databases, personally identifiable information and internal email [19]. In at least one case a malicious executable named main.exe pulled data from Microsoft OneDrive and SharePoint, and compressed archives went to Mega, with exfiltrated volume reaching tens of terabytes [20][21]. Encryption uses ChaCha20 and RSA-4096, with the .ENCRT extension observed and a July 2025 sample using .CRYPT [22][23]. Windows Management Instrumentation deletes volume shadow copies before encryption, and one victim had backup and archived data deleted from both primary and disaster recovery infrastructure [24][25].
Victims appear on the Tor leak site from Africa, the Americas, the Asia-Pacific, Europe and the Middle East, across healthcare, financial services and insurance, critical manufacturing, transportation, government, utilities, academia, media, retail and nonprofit services [26][27][28]. "Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations," said Chris Butera, CISA's acting assistant director for cybersecurity [29].
The attribution edge is thinner. Research published in July by AhnLab found overlap between Gunra and Lazarus Group without naming the latter, concluding the two appear to be separate actors with different objectives that may have shared techniques, tools and infrastructure or collaborated to a limited extent [30][31]. CyberScoop characterizes the alert as saying Gunra benefits from North Korean government-linked hackers' tools, and notes such collaboration dates back to at least 2024 [32][33].
What to watch: whether the Golden Community brand accumulates its own victim list separate from Gunra's, and whether the builder produces enough payload variation to break the .ENCRT and .CRYPT indicators. The advisory's own advice is dull and correct: patch known exploited vulnerabilities on VPN and RDP-exposed systems, keep offline immutable backups in segmented locations, segment networks, audit AD for unrecognized accounts and admin privileges, require MFA, and test controls against the mapped MITRE ATT&CK techniques [34][35][36][37].
Ranked by verification strength, evidence, and original report placement.
A joint #StopRansomware advisory on Gunra ransomware was published August 10, 2026.
The advisory was produced by CISA with the Department of Defense's Cyber Crime Center, FBI, National Security Agency, Secret Service and the Republic of Korea's National Police Agency.
The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant derived from leaked Conti ransomware source code.
According to the agencies, Gunra is based on or influenced by the Conti ransomware code leaked in 2022.
By January 2026, Gunra had launched a formal ransomware-as-a-service affiliate program, according to the advisory.
The ransomware-as-a-service affiliate program was advertised on dark web forums.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 10, 2026
1 article · August 11, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Strong single-document provenance, corroborated by two independent recaps
Nearly every claim traces to one primary artefact — a six-agency joint advisory — but that artefact is government-authored, names specific CVEs, tooling, algorithms and file extensions, and is independently summarized by two publishers whose non-overlapping details are mutually consistent. Ceiling is set by the fact that no source outside the advisory (except AhnLab's hedged July research) independently verifies the technical findings.
Operating affiliate business with multi-region victims, but no counts disclosed
Adoption here is criminal-ecosystem uptake: a formal affiliate program with panel, builder and documentation, a rebrand to Golden Community, a recruitment channel for initial access brokers, leak-site victims across five regions and roughly a dozen sectors, and multiple documented intrusion cases including tens-of-terabytes exfiltration. What is missing is scale: no victim count, affiliate count, ransom revenue or dwell-time figures appear in either source.
Mostly proportionate, with one attribution claim running ahead of its research
The technical body of the story is closely tied to advisory text, and the cluster's own 'franchise' framing is supported by the panel/builder/affiliate package and the nine-month interval. The overstatement is narrow but real: the assertion that Gunra 'benefits from North Korean government-linked hackers' tools' is single-publisher and firmer than the AhnLab conclusion it cites, which says the actors appear separate and may only have shared tooling to a limited extent. The advisory's own official framing is deliberately unglamorous — 'another variant in the ongoing trend'.
Advisory and vendor-research incentives visible, but no commercial pitch in the reporting
The primary source is a government advisory whose purpose is to drive patching and hardening behaviour, so its emphasis is intrinsically prescriptive, and it is quoted by a named CISA official. The cited AhnLab research is vendor-produced threat intelligence, which carries a visibility interest, and both publishers are security trade outlets covering an alert on publication day. No source in the cluster sells a product against Gunra or discloses funding, pricing or sponsorship, which keeps distortion moderate rather than high.
High confidence on advisory content, lower on state-actor nexus and scale
Two independent publishers agree on every overlapping element, and the specific, falsifiable technical details make the advisory-derived claims reliable. Confidence is reduced by dependence on one primary document, the absence of any quantitative victim or revenue scale, and the unresolved North Korean tooling attribution.
Follow any of these and your For You feed starts watching them — no settings page required.
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher
security
Two years, 117 identified children: the only Com case this week with an outcome attached1 distinct publisher
build
AI-written snap7 scripts move the scarce resource in OT attacks from skill to exposure2 distinct publishers
security
Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held6 distinct publishers