
The Actor: Who Is Gunra?
On August 10, 2026, the FBI, CISA, Department of Defense Cyber Crime Center (DC3), NSA, and U.S. Secret Service, alongside the Republic of Korea National Police Agency, issued a joint Cybersecurity Advisory warning organizations about the emerging Gunra ransomware threat. The advisory highlights attacks against government, critical infrastructure, and other organizations worldwide and details the group’s evolving tactics, techniques, and procedures.
First observed by the FBI in April 2025, Gunra has since expanded into a ransomware-as-a-service (RaaS) operation that uses double extortion, stealing sensitive information before encrypting systems and threatening to publish the data if victims refuse to pay. Initially focused on Windows environments, Gunra introduced a Linux variant in mid-2025 and moved toward broader cross-platform targeting.
Data Theft Before Encryption: Exfiltration Is Central To Gunra’s Strategy
Gunra actors collect business-critical documents, databases, personally identifiable information, and internal email before deploying ransomware. The FBI has observed a malicious tool designed specifically to steal data from Microsoft OneDrive and SharePoint.
In one known incident, attackers compressed sensitive information and transferred it to the MEGA file-sharing service, with stolen data reaching tens of terabytes. Gunra infrastructure has also been associated with legitimate tools including 7-Zip, RClone, and FileZilla. This focus on data theft means organizations may face significant exposure even if encrypted systems can ultimately be restored.
Evolving TTPs: What Makes Gunra Dangerous
Gunra actors primarily gain access by exploiting vulnerabilities in internet-facing firewall and VPN appliances. The joint advisory highlights CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws affecting certain FortiOS and FortiProxy versions.
Once inside, attackers have used Impacket tools including psexec.py and smbclient.py for lateral movement over SMB. Investigators also documented abuse of default VPN administrator credentials, SSH tunneling for persistence, stolen session information, and RDP access to critical systems.
Before encryption, Gunra actors have used WMI to delete Windows volume shadow copies and have deleted backup and archived data from backup infrastructure, limiting recovery options. The combination of compromised credentials, legitimate administrative utilities, cloud services, and cross-platform ransomware makes Gunra difficult for traditional signature-based defenses to contain.
The BlackFog Perspective: BlackFog’s Real-Time Defense For Risk Mitigation
Stops data theft before encryption: BlackFog’s anti data exfiltration (ADX) technology directly addresses Gunra’s double-extortion model. By preventing unauthorized outbound transfers, organizations can disrupt the stage of the attack that gives Gunra its greatest leverage.
Identifies abnormal behavior in real-time: Gunra affiliates use compromised accounts, SMB, RDP, SSH tunneling, and legitimate administrative tools to move through victim environments. Behavioral analytics help identify anomalous activity before attackers broaden their access.
Cuts off cloud and file-transfer exfiltration: Gunra has targeted OneDrive and SharePoint and used services and utilities such as MEGA, RClone, and FileZilla. BlackFog monitors outbound data movement and blocks suspicious transfers, even where legitimate applications are being abused.
Reduces exposure before ransomware deployment: Gunra may spend significant time gathering credentials, collecting data, and targeting backups before encryption begins. BlackFog’s prevention-first approach focuses on stopping malicious activity earlier in the attack chain.
Share This Story, Choose Your Platform!
Related Posts
Gunra Ransomware: Why Stopping Data Exfiltration Matters Before Encryption Begins
Gunra ransomware steals critical data before encryption. Learn how to stop this emerging double extortion threat with anti data exfiltration.
Claude Coding Jailbreak: Latest Risks And Enterprise Impact
Claude coding jailbreaks: recent research, how enterprises can reduce artificial intelligence (AI) security risks with better monitoring and governance.
What Are The Advantages Of Using AI In Intrusion Detection?
Explore the advantages of AI in intrusion detection, from faster analysis and greater scale to identifying previously unseen attack patterns.
How Can Cybersecurity Professionals Defend Against Threats Posed By Malicious AI Tools?
Learn how cybersecurity professionals can defend against malicious AI tools with AI-specific monitoring, least-privilege access and outbound visibility.
Are There Any Government Policies On Using AI For Cybersecurity?
Learn how the EU AI Act and US NIST frameworks address the use of AI in cybersecurity and what their different approaches mean for businesses.
Can AI Be Used To Effectively Prevent Cyberattacks?
AI helps prevent cyberattacks by spotting threats without known signatures, but it works best alongside human oversight, governance and a layered strategy.





