Gunra Ransomware: RaaS Exploiting FortiGate for VDI Sessions, OTP Theft, SaaS Exfiltration, and Encryption
1. Basic Information
Severity: Critical
Title: #StopRansomware: Gunra Ransomware (AA26-222A)
Publishers: CISA / FBI / DC3 / NSA / USSS / Korean National Police Agency (KNPA)
Publication Date: 2026-08-10
Original Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
Primary PDF: https://media.defense.gov/2026/Aug/10/2003976697/-1/-1/0/CSA_STOPRANSOMWARE_GUNRA_RANSOMWARE.PDF
Related Sources:
NSA Announcement: https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4567025/nsa-joins-fbi-and-others-in-releasing-guidance-to-defend-against-gunra-ransomwa/
BleepingComputer: https://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/
Related Malware, Groups, CVEs, and Products: Gunra, Golden Community, Conti variant, CVE-2024-55591, C
Discussion
Jump in and comment!
Get the ball rolling with your comment!