(TLP:CLEAR) CISA, FBI, and Partners Warn of Gunra Ransomware
Created: Thursday, August 13, 2026 - 15:19
Categories: Cybersecurity, Federal & State Resources, Security Preparedness
Summary: This week, CISA, along with federal and international partners, released a joint #StopRansomware advisory on Gunra, a ransomware-as-a-service (RaaS) operation. Gunra first appeared in April 2025 as a double-extortion variant derived from the leaked Conti source code and expanded to a formal affiliate program in early 2026, at times operating under the alias “Golden Community.” Affiliates exploit known vulnerabilities in internet-facing devices, including Fortinet appliances (CVE-2024-55591 and CVE-2025-24472), then exfiltrate data before encrypting systems and threaten to publish stolen files on a dedicated leak site if victims do not pay.
Analyst Note: Gunra’s playbook maps closely to risks facing water and wastewater utilities. The actors favor VPN gateways, RDP-exposed infrastructure, and unpatched edge devices for initial access. The advisory notes the group targets utilities among other sectors, and its model of stealing data before encrypting systems can disrupt both IT and connected OT environments.
The advisory also flags a useful defender opportunity: researchers found the Gunra Linux variant uses a weak, time-seeded random number generator, which may allow key reconstruction and file recovery without paying.
While Linux ransomware is less frequent, it carries the potential for a higher impact than its Windows counterpart. Likewise, the primary concern is not a fleet-wide Linux desktop infection; it is the loss of central services hosted on Linux, container platforms, storage infrastructure, and virtualized environments, such as ESXi.
Original Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
Additional Reading:
Related WaterISAC PIRs: 6, 7, 7.1, 8, 10, 10.2, 12
