By |Last Updated: September 29th, 2026|4 min read|Categories: Breach, Data Exfiltration, Exploits, Uncategorized|

threat intelligence brief · gunra ransomware

Sector

Government · Critical Infrastructure · Healthcare · Financial Services

Brief

A joint advisory from the FBI, CISA, DC3, NSA, U.S. Secret Service and the Republic of Korea National Police Agency details an emerging ransomware-as-a-service operation built on double extortion. Business-critical data, in one case tens of terabytes, is stolen before encryption ever begins.

The Actor: Who Is Gunra?

On August 10, 2026, the FBI, CISA, Department of Defense Cyber Crime Center (DC3), NSA, and U.S. Secret Service, alongside the Republic of Korea National Police Agency, issued a joint Cybersecurity Advisory warning organizations about the emerging Gunra ransomware threat. The advisory highlights attacks against government, critical infrastructure, and other organizations worldwide and details the group’s evolving tactics, techniques, and procedures.

First observed by the FBI in April 2025, Gunra has since expanded into a ransomware-as-a-service (RaaS) operation that uses double extortion, stealing sensitive information before encrypting systems and threatening to publish the data if victims refuse to pay. Initially focused on Windows environments, Gunra introduced a Linux variant in mid-2025 and moved toward broader cross-platform targeting.

Data Theft Before Encryption: Exfiltration Is Central To Gunra’s Strategy

Gunra actors collect business-critical documents, databases, personally identifiable information, and internal email before deploying ransomware. The FBI has observed a malicious tool designed specifically to steal data from Microsoft OneDrive and SharePoint.

In one known incident, attackers compressed sensitive information and transferred it to the MEGA file-sharing service, with stolen data reaching tens of terabytes. Gunra infrastructure has also been associated with legitimate tools including 7-Zip, RClone, and FileZilla. This focus on data theft means organizations may face significant exposure even if encrypted systems can ultimately be restored.

threat snapshot

APR 2025: First observed by the FBI, before expanding into a RaaS operation


10s of TB: Stolen data transferred to MEGA in a single known incident


2 CVEs: Authentication bypass flaws named in the joint advisory

Evolving TTPs: What Makes Gunra Dangerous

Gunra actors primarily gain access by exploiting vulnerabilities in internet-facing firewall and VPN appliances. The joint advisory highlights CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws affecting certain FortiOS and FortiProxy versions.

Once inside, attackers have used Impacket tools including psexec.py and smbclient.py for lateral movement over SMB. Investigators also documented abuse of default VPN administrator credentials, SSH tunneling for persistence, stolen session information, and RDP access to critical systems.

Before encryption, Gunra actors have used WMI to delete Windows volume shadow copies and have deleted backup and archived data from backup infrastructure, limiting recovery options. The combination of compromised credentials, legitimate administrative utilities, cloud services, and cross-platform ransomware makes Gunra difficult for traditional signature-based defenses to contain.

Tools and Services Observed In Gunra Activity Box

OneDrive · SharePoint · MEGA · 7-Zip · RClone · FileZilla · Impacket · psexec.py · smbclient.py · WMI · FortiOS · FortiProxy

The BlackFog Perspective: BlackFog’s Real-Time Defense For Risk Mitigation

Stops data theft before encryption: BlackFog’s anti data exfiltration (ADX) technology directly addresses Gunra’s double-extortion model. By preventing unauthorized outbound transfers, organizations can disrupt the stage of the attack that gives Gunra its greatest leverage.

Identifies abnormal behavior in real-time: Gunra affiliates use compromised accounts, SMB, RDP, SSH tunneling, and legitimate administrative tools to move through victim environments. Behavioral analytics help identify anomalous activity before attackers broaden their access.

Cuts off cloud and file-transfer exfiltration: Gunra has targeted OneDrive and SharePoint and used services and utilities such as MEGA, RClone, and FileZilla. BlackFog monitors outbound data movement and blocks suspicious transfers, even where legitimate applications are being abused.

Reduces exposure before ransomware deployment: Gunra may spend significant time gathering credentials, collecting data, and targeting backups before encryption begins. BlackFog’s prevention-first approach focuses on stopping malicious activity earlier in the attack chain.

BlackFog Vs Gunra Ransomware

Initial Access: Exploited internet-facing VPN and firewall systems, compromised credentials.

BlackFog Countermeasure: Behavioral detection, access anomaly monitoring, exposure reduction.


Lateral Movement: Impacket, SMB, RDP, SSH tunneling.

BlackFog Countermeasure: Behavioral analytics, traffic control, rapid containment.


Data Collection & Exfiltration: OneDrive, SharePoint, MEGA, RClone, FileZilla.

BlackFog Countermeasure: Behavioral monitoring, Anti data exfiltration (ADX), Data loss prevention.

BlackFog is the category-defining vendor in anti data exfiltration (ADX). Founded in 2015, the company invented ADX on the thesis that the endpoint is the only control point capable of stopping data from leaving an organization, an architectural bet that has now been validated across three exfiltration vectors: ransomware, shadow AI, and autonomous AI agents. BlackFog’s endpoint-native platform protects more than 500 enterprises, government agencies, and critical infrastructure operators worldwide. The company is the publisher of the annual State of Ransomware report and the BlackFog/Sapio Shadow AI Research, the most-cited primary research in the category. BlackFog’s recognition includes the teiss Awards 2026, the AI Excellence Award 2026, the Cybersecurity Excellence Awards 2026, and the Cybersecurity Breakthrough Award. Headquartered in San Francisco with international operations in London and Belfast. Learn more at blackfog.com.

Share This Story, Choose Your Platform!

Related Posts