Extortion tactics: FBI puts govts on high alert over ongoing Gunra attacks
This story has significance for readers across Kenya and beyond.
- The FBI and CISA jointly warned organisations about Gunra, a ransomware group first observed in April 2025 that has struck victims across multiple continents
- Gunra expanded into a ransomware-as-a-service programme in January 2026, recruiting hackers to breach enterprise networks under the alias Golden Community
- Authorities linked attacks to specific authentication-bypass vulnerabilities in FortiOS and FortiProxy systems used to gain initial access
The FBI, alongside several US and South Korean security agencies, has issued a joint advisory warning organisations worldwide about Gunra, a rapidly expanding ransomware operation that has targeted critical infrastructure sectors and governments across at least ten industries.
The advisory, published on 10 August 2026, was co-signed by the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), the Department of Defense Cyber Crime Center, the National Security Agency, the US Secret Service, and South Korea's National Police Agency.
It warns that individual Gunra attacks have involved the theft of tens of terabytes of data, with ransom demands opening at amounts exceeding tens of millions of dollars.
How Gunra Operates
Investigators first detected Gunra activity in April 2025. By January 2026, the group had evolved into a ransomware-as-a-service (RaaS) model, supplying affiliates with ransomware builders and both Windows and Linux payloads.
Operating under the alias Golden Community, the gang has also recruited testers and ethical hackers to compromise enterprise networks on its behalf.
The ransomware is believed to draw heavily from the Conti source code that leaked in 2022. Gunra employs double extortion tactics, stealing sensitive data before encrypting systems and threatening to publish or sell the information if victims refuse to pay. Victims are typically given five to seven days to negotiate via Tor or the qTox messaging platform.
Authorities traced initial access in many incidents to two authentication-bypass vulnerabilities, CVE-2024-55591 and CVE-2025-24472, affecting certain FortiOS and FortiProxy versions.
Attackers have also exploited default credentials, compromised administrator accounts, hijacked user sessions, and manipulated authentication systems to allow attacker-controlled one-time passwords to bypass multi-factor authentication.
Tools Used and Sectors Affected
Once inside a network, Gunra operators deploy tools including Impacket, Mimikatz, RClone, FileZilla, 7-Zip, AnyDesk, and Sliver to harvest credentials, move laterally, and exfiltrate data.
A malicious utility called main.exe was used in some attacks to extract files from Microsoft OneDrive and SharePoint, with stolen archives subsequently uploaded to the Mega file-sharing platform.
Files are encrypted using ChaCha20 and RSA-4096 algorithms and typically receive the .ENCRT extension, with a ransom note labelled R3ADM3.txt left behind.
In at least one documented case, attackers destroyed backup data at both primary and disaster-recovery sites before and after deploying the ransomware.
Victims have been recorded across the Americas, Europe, the Middle East, Africa, and Asia-Pacific, spanning sectors including healthcare, finance, government, manufacturing, transportation, utilities, and retail.
What Organisations Should Do
The agencies urged organisations to immediately patch known vulnerabilities in internet-facing VPN and remote-access systems, remove default credentials, segment networks, and maintain tested offline backups that are fully isolated from production environments.
Security teams should also scrutinise unexpected privileged accounts and monitor unusual access patterns across VPN, virtual desktop infrastructure, OneDrive, and SharePoint environments.
Source: TUKO.co.ke
Reporting originally appeared via TUKO. Read the full source for additional context.