Gunra Ransomware RaaS Targeting Critical Infrastructure
Score: 9/10

Gunra Ransomware RaaS Targeting Critical Infrastructure

Gunra is a sophisticated RaaS variant derived from Conti source code that utilizes Fortinet exploits and multi-threaded encryption to target global critical infrastructure.

Executive Summary

Gunra emerged in April 2025 as a sophisticated ransomware-as-a-service (RaaS) operation derived from leaked Conti source code. Operating under aliases such as Golden Community, the group employs a double-extortion model, exfiltrating massive volumes of data before deploying high-speed multi-threaded encryption using ChaCha20 and RSA-4096. A joint report titled 'Operação Double Barrel' has notably suggested links between Gunra and state-sponsored threat actors.

Technically, Gunra specializes in the exploitation of internet-facing appliances, particularly Fortinet devices, using vulnerabilities like CVE-2024-55591 and CVE-2025-24472 to establish persistent superuser access via a rogue 'forticloud-sync' account. They leverage common tools such as Impacket for lateral movement and RClone for data exfiltration to cloud services like Mega. Interestingly, a cryptographic weakness in the Linux variant's PRNG implementation may allow for data recovery without ransom payment.

Gunra poses a significant risk to critical infrastructure sectors including healthcare, financial services, and manufacturing across the Americas, Europe, and Asia-Pacific. The group's ability to bypass MFA through VDI session hijacking and their aggressive destruction of volume shadow copies and backups makes them a high-priority threat for organizations utilizing Fortinet and VDI infrastructure.

Key Details

Threat Name

Gunra Ransomware

Affects

Fortinet

Adversary

Gunra

MITRE Techniques

—

Malware/Tools

Gunra, Conti, Impacket, RClone

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance9
Enterprise Relevance10
Clarity & Structure9
Technical Depth8

Sources