Background and Threat Evolution
A joint alert about a sudden increase in Gunra ransomware assaults was released on August 10, 2026, by US and South Korean cybersecurity officials, including CISA, the FBI, the NSA, and the National Police Agency. What had begun as a strain based on leaked Conti source code in early 2025 had developed into a complete Ransomware-as-a-Service model. In order to attract talented hackers who can infiltrate larger networks, the gang promises affiliates an alluring 80% portion of extortion rewards. Equipped with these collaborations, Gunra operatives have methodically attacked vital infrastructure targets throughout the globe, jeopardizing everything from government services and transportation to healthcare and banking.
Technical Operations and Individual Protective Measures
The FortiOS and FortiProxy vulnerabilities CVE-2024-55591 and CVE-2025-24472, which are known flaws in edge devices like firewalls and VPNs, are frequently the first targets of Gunra assaults. Once inside, they move quickly to conceal their identity by deleting command history and event logs before using well-known cloud services like Mega and OneDrive to set up private files for exfiltration. The company engages in double extortion by locking down Windows and Linux computers and threatening to reveal stolen data unless a ransom is paid within a week. To adhere to baseline security standards and safeguard specific systems, users should update software on a regular basis, enable multi-factor authentication for all accounts, maintain separate offline backups, and be on the lookout for phishing attempts.
Author Notes
Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), et al., #StopRansomware: Gunra Ransomware, Cybersecurity Advisory AA26-222A (August 10, 2026), cisa.gov/news-events/cybersecurity-advisories/aa26-222a.
About the Author
Carmen Estela is a Cybersecurity Research Analyst at Cyber Defense Magazine and a Women in Cybersecurity Award Candidate. She recently graduated with a Master of Science degree from the University of Central Florida and holds a Bachelor’s degree in Criminology from the University of Florida with certifications in Data Analytics and AI Fundamentals. She frequently speaks and volunteers at well-known industry gatherings, such as BSides Orlando and BSides Jax, where she offers her perspectives on emerging cyber trends. Carmen is committed to advancing the standards of governance, risk, and compliance within cybersecurity. She has also served as an adult protective investigator, police dispatcher, and legal intern, applying investigative skills across law enforcement, academic, and public service settings.
Reach her online at [email protected].

