Gunra ransomware actors exfiltrated up to tens of terabytes from one victim before encryption, according to a joint CISA, FBI, DC3, NSA, USSS, and Korean National Police Agency advisory. In another documented case, they deleted backup and archived data at both the primary and disaster recovery data centers.
The chain can begin at the network edge. The agencies observed exploitation of two FortiOS and FortiProxy authentication bypasses, exposed VPN weaknesses, default credentials, and stolen sessions. The operation then reached VDI, Active Directory, OneDrive, SharePoint, database servers, and network-attached storage.
The advisory describes Gunra as “a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations.” Its authors observed victims across the Americas, Europe, the Middle East, Africa, and Asia-Pacific. They did not publish an aggregate victim count.
Edge appliances open the path
The FBI observed Gunra exploiting CVE-2024-55591 and CVE-2025-24472 against internet-facing Fortinet systems. Fortinet’s PSIRT advisory says crafted Node.js websocket or CSF proxy requests can give a remote attacker super-admin privileges and confirms exploitation in the wild.
The affected version boundaries are narrow. FortiOS 7.0.0 through 7.0.16 must move to 7.0.17 or later. FortiProxy 7.2.0 through 7.2.12 must move to 7.2.13 or later, and FortiProxy 7.0.0 through 7.0.19 must move to 7.0.20 or later. Those fixed floors supersede every earlier release in the affected branches. Fortinet lists FortiOS 6.4, 7.2, 7.4, and 7.6 and FortiProxy 2.0, 7.4, and 7.6 as unaffected by these two flaws.
Fortinet’s device logs offer an early recognition point. Successful administration through ui=“jsconsole” with method=“jsconsole”, a new random administrator, or the persistent account forticloud-sync requires investigation. Values such as 1.1.1.1 or 8.8.8.8 inside those records can be attacker-supplied parameters rather than source addresses, so Fortinet says they must not be blocked as attack infrastructure.
Gunra affiliates also used credential exposure and SSH access-control weaknesses in VPN gateways. One victim had a default SSL-VPN administrator credential and no account lockout. This means a clean CVE inventory does not clear an exposed gateway whose accounts, sessions, or configuration changed.
Stolen sessions outlive MFA
At one victim, the actors reached an internet-connected administrator workstation, opened the SSL-VPN console, and modified an unused account so it could skip a mandatory password change. They used stolen session material to enter VDI and move through RDP to an authentication server, Active Directory, and IT desktops.
The intrusion then crossed the identity layer. Gunra manipulated VPN traffic to collect credentials and sessions sent to a VDI portal, hijacked session cookies, and changed authentication-processing files so an attacker-selected one-time password would always succeed. The actors also stole an encryption key from a Hiware access-control server and decrypted stored enterprise-server credentials.
The FBI observed secretsdump.py against domain controllers and psexec.py plus smbclient.py for lateral movement. OpenSSH provided tunneling. Those names are dual-use tools, so their presence is a search pivot; process ancestry, account use, command lines, destination systems, and timing establish whether they executed as part of the intrusion.
Gunra commonly worked between 10 p.m. and 6 a.m., deleted access logs, and cleared command history. Hunt privileged gateway, VPN, VDI, RDP, and domain-controller activity together. An isolated alert at any one layer can miss the session and credential chain.

Figure details
Gunra affiliates gain edge access through exploited FortiOS or FortiProxy authentication bypasses, exposed VPN weaknesses, or stolen credentials. They create or alter privileged access, use OpenSSH tunnels, steal sessions and directory credentials, and move through VDI, RDP, and SMB. The actors collect OneDrive, SharePoint, and internal files with main.exe and common archive or transfer tools. Before encryption, they delete shadow copies and backup data. The Windows encryptor appends ENCRT and writes R3ADM3.txt. Verification must cover the edge device, privileged identities, cloud transfers, backup integrity, and endpoint artifacts.
Exfiltration reaches cloud data
The FBI observed a malicious main.exe collecting data from OneDrive and SharePoint. Gunra also used 7-Zip, RClone, FileZilla, and Mega during collection and exfiltration. One victim’s compressed archives reached up to tens of terabytes.
KNPA documented the actors entering IT staff VDI desktops and stealing system and network configuration documents. Credentials taken from the access-control server then enabled ransomware deployment against database servers and network-attached storage. This sequence makes cloud transfer, unusual archive creation, and privileged storage access pre-encryption signals.
The Windows encryptor traverses accessible drive letters from A through Z, skips common system directories and executable file types, and queues user data for parallel ChaCha20 plus RSA-4096 encryption. It appends .ENCRT; one July 2025 sample used .CRYPT. Each encrypted directory receives R3ADM3.txt.
Before encryption, Gunra used this command signature to delete a specific volume shadow copy:
cmd.exe /c C:\Windows\System32\wbem\WMIC.exe shadowcopy where "ID='{guid of shadowcopy}'" delete
The self-contained encryptor can finish without DNS or HTTP traffic. Backup deletion, discovery across many drive letters, high-volume file opens, new .ENCRT files, and R3ADM3.txt are stronger local signals than waiting for a command-server connection.
Gunra leaves exact artifacts
CISA’s complete public-tool hunting set is FileZilla, Amass, RClone, Sliver, 7-Zip, WinRAR, DBeaver, Slack, Microsoft Visual Studio Code, MobaXterm, AnyDesk, Google Remote Desktop, Mimikatz, and the Impacket suite. These applications have legitimate uses. Treat their presence as a hunting lead only when account activity, execution context, destinations, or timing connect them to the intrusion.
CISA marks the network indicators as potentially historical. Vet them against time, ownership, direction, and surrounding activity before blocking:
- IP addresses:
23.239.119[.]2,23.239.119[.]3,23.239.119[.]4,23.239.119[.]5,23.239.119[.]6,86.54.28[.]216,103.125.234[.]14,70.36.99[.]82,211.21.210[.]181,123.184.143[.]105,182.204.21[.]240,182.204.16[.]112,123.244.187[.]144,182.204.39[.]118,67.43.53[.]10,123.246.37[.]108, and91.201.66[.]146. - Domains:
datapub[.]news,gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad[.]onion,lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd[.]onion, andnsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd[.]onion. - Negotiation email accounts:
[email protected],[email protected],[email protected], and[email protected]. - qTox IDs:
2507312EC10BB44ED9DAA04E3C5C27E8C13154649B1A02E73ACFAE1681EE0208D05133A8FB22,0FE87CED0C611AE97E049C64288557F49E8271E91399E849328B078DA789A573031783235BEF,47829AF1C943D4C296C910706923AS199BDA4995B076ED9A9016F7DEF161D445DF00F13E6900, and9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47. - SHA-256 values:
2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751and834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1formain.exe;91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0forcryptor.exe; anda82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9formsmp.exe. - Endpoint and account markers:
forticloud-sync,.ENCRT,.CRYPT,.GNRA, andR3ADM3.txt.
The Linux ELF variant adds a recovery opportunity. CISA says its encryption key uses a predictable srand(time(NULL)) seed. Preserve encrypted files, timestamps, ransom notes, and system logs so responders can attempt mathematical key reconstruction. That weakness does not apply to the Windows encryptor and does not guarantee recovery.
Verify edge, identity, and recovery
Begin with every internet-facing firewall, proxy, VPN, and RDP path. Confirm affected Fortinet branches run at least FortiOS 7.0.17, FortiProxy 7.2.13, or FortiProxy 7.0.20. Where immediate upgrading is impossible, Fortinet recommends disabling HTTP and HTTPS administration or restricting it with local-in policies. The update remains required.
Audit new and altered administrators, jsconsole logins, forticloud-sync, VPN policy changes, session reuse, VDI portal files, unexpected OTP success, domain credential dumping, RDP and SMB movement, OpenSSH tunnels, archive creation, Mega, OneDrive, and SharePoint transfers. Preserve appliance, identity, endpoint, cloud, and backup evidence before eviction.
Test recovery from an immutable, segmented copy that ransomware administrators cannot reach. Verify shadow copies and primary and disaster recovery backups from a clean administrative system.
The expected result is exact: affected edge devices report fixed releases, privileged identity changes have approved owners, no unexplained Gunra pivots remain in retained evidence, cloud transfers match business activity, and a clean restore test succeeds. Any unexplained administrator, session, archive, or backup deletion keeps the response open for containment and scoping.
