Executive Summary
Gunra emerged in April 2025 as a sophisticated ransomware-as-a-service (RaaS) operation derived from leaked Conti source code. Operating under aliases such as Golden Community, the group employs a double-extortion model, exfiltrating massive volumes of data before deploying high-speed multi-threaded encryption using ChaCha20 and RSA-4096. A joint report titled 'Operação Double Barrel' has notably suggested links between Gunra and state-sponsored threat actors.
Technically, Gunra specializes in the exploitation of internet-facing appliances, particularly Fortinet devices, using vulnerabilities like CVE-2024-55591 and CVE-2025-24472 to establish persistent superuser access via a rogue 'forticloud-sync' account. They leverage common tools such as Impacket for lateral movement and RClone for data exfiltration to cloud services like Mega. Interestingly, a cryptographic weakness in the Linux variant's PRNG implementation may allow for data recovery without ransom payment.
Gunra poses a significant risk to critical infrastructure sectors including healthcare, financial services, and manufacturing across the Americas, Europe, and Asia-Pacific. The group's ability to bypass MFA through VDI session hijacking and their aggressive destruction of volume shadow copies and backups makes them a high-priority threat for organizations utilizing Fortinet and VDI infrastructure.
Key Details
Threat Name
Gunra Ransomware
Affects
Fortinet
Adversary
Gunra
MITRE Techniques
—
Malware/Tools
Gunra, Conti, Impacket, RClone
