
Gunra Ransomware Shifts to Affiliate Model
By early 2026, the group had expanded through a formal ransomware-as-a-service affiliate program advertised on with a management panel, configurable ransomware builder, cross-platform locker payloads and affiliate documentation. The FBI also observed Gunra operating under new branding aliases, including Golden Community, while recruiting penetration testers and ethical hackers as initial access brokers.
Gunra initially focused on Windows environments before introducing a Linux variant and moving toward broader cross-platform targeting.
Victims observed on the group’s dedicated leak site include organizations across the Americas, Europe, the Middle East, Africa and the Asia-Pacific.
Targeted sectors include healthcare and public health, financial services and insurance, critical manufacturing, transportation, government services, utilities, academia, media and communications, retail, and professional and nonprofit services.

VPN Vulnerabilities Used for Initial Access
According to the advisory, Gunra actors primarily gained initial access by exploiting known .
After gaining access, attackers used tools including Impacket utilities to move laterally through victim networks using SMB. In one case, actors compromised an SSL-VPN appliance using default credentials where account lockout controls were absent. They later used stolen session information to access internal virtual desktop infrastructure and move through systems including Active Directory servers and IT personnel workstations.
Data Theft Precedes Encryption
The double-extortion from Microsoft OneDrive and SharePoint. Compressed archives containing sensitive information were also transferred to the Mega file-sharing service, with the volume of exfiltrated data reaching tens of terabytes.
For encryption, Gunra uses ChaCha20 and RSA-4096 algorithms and has been observed using the
.ENCRT extension for encrypted files. A documented sample from July 2025 used the .CRYPT extension. The ransomware also uses Windows Management Instrumentation to delete volume shadow copies before encryption, while one victim had backup and archived data deleted from both primary and disaster recovery infrastructure.Agencies Urge Patching and Network Segmentation
The authoring agencies recommend that organizations prioritize patching known exploited vulnerabilities in internet-facing systems, including and limit the spread of ransomware between systems.
The agencies also recommend reviewing domain controllers, servers, workstations and Active Directory environments for unrecognized accounts, auditing administrative privileges, requiring MFA where possible and testing security controls against the Gunra techniques mapped to the MITRE ATT&CK framework.
The joint advisory was published August 10, 2026, as part of the ongoing #StopRansomware initiative.
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf thecyberexpress.com.
SOCIAL SHARE CARD GENERATOR