Full Report
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of
Analysis Summary
# Incident Report: Gunra Ransomware Campaign Targeting Critical Infrastructure
## Executive Summary
Gunra ransomware is a Conti-derived operation employing a double-extortion model to target critical infrastructure sectors globally, including healthcare, finance, and government services. The threat actors exploit vulnerabilities in internet-facing appliances and utilize phishing to gain initial access, subsequently exfiltrating terabytes of data before deploying encryption. While the group has claimed over 51 victims since April 2025, a significant cryptographic flaw in their Linux variant allows for data recovery without ransom payment.
## Incident Details
- **Discovery Date:** April 2025 (Initial emergence); August 11, 2026 (Joint Advisory)
- **Incident Date:** Ongoing (Active recruitment noted January 2026)
- **Affected Organization:** 51+ organizations (e.g., Golden Community rebranding)
- **Sector:** Healthcare, Financial Services, Government, Public Health, Nonprofit
- **Geography:** Global (Primary: South Korea, Brazil, Spain, Thailand, Hong Kong, Australia, Europe; Secondary: US/Canada)
## Timeline of Events
### Initial Access
- **Date/Time:** April 2025 – Present
- **Vector:** Exploitation of edge devices and Phishing
- **Details:** Attackers exploit CVE-2024-5559 (Schneider Electric PowerLogic P5) and CVE-2025-24472 (Fortinet FortiOS/FortiProxy). Phishing is also used to deliver malicious payloads.
### Lateral Movement
- **Details:** Attackers utilize Impacket libraries, specifically `psexec.py` and `smbclient.py`, to move across the network via the SMB protocol.
### Data Exfiltration/Impact
- **Details:** Threat actors exfiltrate data from Microsoft OneDrive and SharePoint using a specialized executable (`main.exe`). Large volumes of data (terabytes) are compressed and uploaded to the MEGA file-sharing service.
### Detection & Response
- **Detection:** Identified by CISA, FBI, and South Korean intelligence through monitoring of data leak sites and affiliate recruitment on dark web forums.
- **Response:** Joint cybersecurity advisory issued by CISA and FBI; research by Breakglass Intelligence identified a flaw in the Linux variant’s encryption.
## Attack Methodology
- **Initial Access:** Vulnerability exploitation (Fortinet, Schneider Electric) and Phishing.
- **Persistence:** RaaS affiliate management panel and cross-platform locker payloads.
- **Privilege Escalation:** Credential dumping via Impacket’s `secretsdump.py`.
- **Defense Evasion:** Deletion of system/network access logs, clearing command history, and operating during off-peak hours (10 p.m. – 6 a.m.).
- **Credential Access:** Extraction of NTDS.dit password hashes from compromised Domain Controllers.
- **Discovery:** Internal infrastructure reconnaissance performed during night shifts.
- **Lateral Movement:** SMB protocol exploitation using Impacket tools.
- **Collection:** Gathering data from cloud environments (OneDrive/SharePoint).
- **Exfiltration:** Large-scale data compression and transfer to MEGA.nz.
- **Impact:** Double extortion (Encryption via Salsa20/ChaCha20 and public data leaking).
## Impact Assessment
- **Financial:** High potential; 5-7 day payment window before data publication.
- **Data Breach:** High; terabytes of sensitive data exfiltrated per victim.
- **Operational:** Severe; encryption of critical files (up to 9TB) causing service disruption.
- **Reputational:** High; branding as "Golden Community" and use of public leak sites.
## Indicators of Compromise
- **Network indicators:**
- MEGA[.]nz (Exfiltration destination)
- WhatsApp-themed chat panels (Negotiation)
- **File indicators:**
- `main.exe` (Exfiltration tool)
- `psexec.py`, `smbclient.py`, `secretsdump.py` (Impacket suite)
- **Behavioral indicators:**
- Spikes in SMB traffic.
- Log deletion activity.
- High-volume data transfers to file-sharing sites between 10 p.m. and 6 a.m.
## Response Actions
- **Containment:** Patching of CVE-2024-5559 and CVE-2025-24472.
- **Eradication:** Removal of Impacket tools and unauthorized "main.exe" files.
- **Recovery:** For Linux-based victims, utilize the "time-seeded rand" cryptographic flaw identified by researchers to decrypt files without payment.
## Lessons Learned
- **Patch Management:** Delayed patching of edge devices (Fortinet/Schneider Electric) remains a primary entry point for RaaS groups.
- **Cryptographic Weakness:** Even sophisticated RaaS groups can make implementation errors; technical analysis of the locker can sometimes yield a free recovery path.
- **Stealth Tactics:** Attackers are specifically timing movements to evade SOC shifts (10 p.m. – 6 a.m.), requiring 24/7 automated monitoring.
## Recommendations
- **Immediate Patching:** Prioritize updates for Fortinet FortiOS/FortiProxy and Schneider Electric PowerLogic P5 appliances.
- **Credential Protection:** Implement MFA and monitor for access to NTDS.dit files on Domain Controllers.
- **Cloud Security:** Restrict and monitor large-scale data downloads/exports from SharePoint and OneDrive.
- **Egress Filtering:** Block or alert on large data transfers to known file-sharing sites like MEGA.