Gunra is a double-extortion ransomware operation that encrypts an organization's files and simultaneously steals data to threaten public leaks unless a ransom is paid. It first appeared in April 2025 as a variant built from the leaked Conti source code, and by January 2026 its operators had formalized it into a ransomware-as-a-service (RaaS) business, advertising a management panel, a configurable payload builder, and cross-platform Windows and Linux encryptors on dark-web forums.
On August 10, 2026, the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and the Republic of Korea's National Police Agency published a joint advisory, #StopRansomware: Gunra Ransomware (Alert Code AA26-222A). The advisory confirms that Gunra affiliates have hit government bodies, critical-infrastructure operators, and commercial organizations across the Americas, Europe, the Middle East, Africa, and Asia-Pacific.
This matters for enterprises because Gunra is not a niche threat run by a single crew. As a service, it lets many affiliates with varying skill levels launch the same professionalized attack chain, which drives up both the volume and the consistency of intrusions. For IT and security leaders in Latin America and the United States, a federal advisory naming your exact sector is a direct signal to validate defenses now. Building resilience against operations like Gunra is the core purpose of an enterprise managed cybersecurity program that combines prevention, detection, and rapid response.
The single most important finding in the Gunra advisory is how the attackers get in: they exploit unpatched, internet-facing firewall and VPN appliances. According to the joint advisory, Gunra actors gained initial access primarily by abusing two authentication-bypass flaws in Fortinet FortiOS and FortiProxy, tracked as CVE-2024-55591 and CVE-2025-24472. Both are design-level authentication failures, and both carry entries in CISA's Known Exploited Vulnerabilities catalog, confirming real-world exploitation.
An authentication-bypass vulnerability is dangerous because it lets an attacker skip the login step entirely and act as a trusted, authenticated user on the edge device that is supposed to protect the network. Once inside that appliance, the attacker is already past the perimeter.
The challenge for most enterprises is not awareness but exposure management. Edge devices are frequently forgotten in patch cycles, run end-of-support firmware, or sit outside centralized monitoring. Every VPN concentrator, firewall, and remote-access gateway facing the public internet is a potential entry point, and multi-site organizations often have dozens spread across regions and operators. Reducing that attack surface requires disciplined patching, tight segmentation, and continuous visibility into what is actually exposed. A resilient managed connectivity and network architecture that centralizes control across sites and carriers makes it far easier to keep every edge device patched, segmented, and monitored rather than left as an open door.
Understanding how Gunra moves through a network is the fastest way to know where to stop it. The advisory describes a consistent kill chain that unfolds in five stages.
First, initial access: affiliates exploit an exposed, vulnerable firewall or VPN appliance to reach the internal network. Second, credential theft: they dump the NTDS.dit database from a domain controller to harvest every account hash in the environment. Third, lateral movement: using pass-the-hash techniques over SMB and RDP, they move from system to system with stolen credentials, escalating toward domain-wide control. Fourth, data exfiltration: before any file is locked, business data is copied out to fuel the extortion threat. Fifth, encryption: Windows systems are encrypted with files appended ".ENCRT" or ".CRYPT", while the Linux variant appends ".GNRA".
Each stage is a detection opportunity. Unusual authentication from an edge device, NTDS access on a domain controller, and mass SMB or RDP connections are all high-fidelity warning signs that appear well before encryption starts. The problem is that these signals are only useful if someone, or something, is watching around the clock. That is precisely the role of a managed SOC with 24/7 SIEM and MDR, which correlates these events, flags the intrusion during the hours-long window between initial access and encryption, and contains it before the ransomware detonates. Notably, the agencies also found a cryptographic weakness in Gunra's Linux encryptor that has let some victims recover files without paying, underscoring why victims should preserve evidence and consult authorities before making any decision.
A layered defense against ransomware protects revenue, reputation, and regulatory standing, not just data. Enterprises that invest ahead of an incident gain concrete, measurable advantages over those that react after encryption.
The first benefit is operational continuity. Immutable, offline backups mean that even if attackers encrypt production systems, clean copies exist that cannot be altered or deleted, allowing recovery in hours rather than weeks. This is the single most reliable defense against double extortion's encryption half, and it is a core outcome of well-designed IT managed services and backup.
The second benefit is reduced dwell time. Because Gunra spends hours moving laterally before encrypting, continuous detection and response dramatically shortens the window in which an attacker operates undetected, often stopping an intrusion before it becomes a business-wide outage.
The third benefit is provable resilience. Network segmentation, enforced multi-factor authentication, disciplined patching of edge devices, and 24/7 monitoring together reduce both the likelihood and the blast radius of an attack. That posture also satisfies cyber-insurance requirements and regulatory expectations, and it protects the customer trust that a public data leak would destroy. In short, a coordinated zero-trust and managed detection strategy converts ransomware from an existential threat into a manageable, contained event.
HIT Communications helps enterprises across Latin America, the United States, and Europe build defenses specifically suited to threats like Gunra. With more than 30 years in enterprise telecom and IT, HIT brings connectivity and security together under one accountable partner, which is exactly what a firewall-to-encryption attack chain demands.
On the prevention side, HIT's managed connectivity and SD-WAN/SASE services centralize control of edge devices across every site and carrier, making consistent patching and segmentation achievable rather than aspirational. On the detection side, HIT's cybersecurity services deliver a managed SOC with SIEM and MDR, giving your organization the round-the-clock monitoring that catches lateral movement in the critical window before encryption. And on the recovery side, HIT's IT managed services implement immutable, tested backups so that a worst-case encryption event becomes a recoverable one.
Because these layers are delivered together, there are no gaps between the network team, the security team, and the recovery plan, which is precisely where ransomware operators thrive. HIT's multilingual teams and regional presence mean enterprises in Colombia, Mexico, Panama, Brazil, the U.S., and Spain get local expertise backed by global-grade tooling.
The Gunra advisory is a clear, time-stamped warning: patch your internet-facing edge, watch for lateral movement, and make sure your backups are immutable. The attack chain is well documented, which means it is also defensible, but only for organizations that act before an affiliate finds their exposed appliance.
The practical next steps are straightforward. Confirm that every Fortinet and other edge device is patched against the known exploited vulnerabilities and removed from direct internet exposure where possible. Verify that multi-factor authentication is enforced everywhere, that your network is segmented to slow lateral movement, and that your SOC has visibility into domain-controller and SMB/RDP activity. Finally, test your ability to restore from immutable backups so recovery is a rehearsal, not a gamble.
If you want an expert review of your exposure to Gunra and similar ransomware operations, contact the HIT Communications team for a consultation. A short assessment now is far cheaper than an incident later, and it is the most direct way to turn a federal advisory into concrete protection for your business.

Find out how we can transform your business. Talk to one of our experts now!
Get in touch