Government agencies traced Gunra from exploited edge devices through credential theft, cloud exfiltration, backup deletion, and cross-platform ransomware.2026-08-12T11:18:00.000Z6 min2026networkidentitythreats
6 min read
Read format

Gunra Steals Cloud Data and Deletes Backups Before Encryption

Government agencies traced Gunra from exploited edge devices through credential theft, cloud exfiltration, backup deletion, and cross-platform ransomware.

By Justin Howe
An unbranded metal network gateway sits in a quiet predawn server room beside one visibly severed blue cable and a red status light.

Gunra ransomware actors exfiltrated up to tens of terabytes from one victim before encryption, according to a joint CISA, FBI, DC3, NSA, USSS, and Korean National Police Agency advisory. In another documented case, they deleted backup and archived data at both the primary and disaster recovery data centers.

The chain can begin at the network edge. The agencies observed exploitation of two FortiOS and FortiProxy authentication bypasses, exposed VPN weaknesses, default credentials, and stolen sessions. The operation then reached VDI, Active Directory, OneDrive, SharePoint, database servers, and network-attached storage.

The advisory describes Gunra as “a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations.” Its authors observed victims across the Americas, Europe, the Middle East, Africa, and Asia-Pacific. They did not publish an aggregate victim count.

Edge appliances open the path

The FBI observed Gunra exploiting CVE-2024-55591 and CVE-2025-24472 against internet-facing Fortinet systems. Fortinet’s PSIRT advisory says crafted Node.js websocket or CSF proxy requests can give a remote attacker super-admin privileges and confirms exploitation in the wild.

The affected version boundaries are narrow. FortiOS 7.0.0 through 7.0.16 must move to 7.0.17 or later. FortiProxy 7.2.0 through 7.2.12 must move to 7.2.13 or later, and FortiProxy 7.0.0 through 7.0.19 must move to 7.0.20 or later. Those fixed floors supersede every earlier release in the affected branches. Fortinet lists FortiOS 6.4, 7.2, 7.4, and 7.6 and FortiProxy 2.0, 7.4, and 7.6 as unaffected by these two flaws.

Fortinet’s device logs offer an early recognition point. Successful administration through ui=“jsconsole” with method=“jsconsole”, a new random administrator, or the persistent account forticloud-sync requires investigation. Values such as 1.1.1.1 or 8.8.8.8 inside those records can be attacker-supplied parameters rather than source addresses, so Fortinet says they must not be blocked as attack infrastructure.

Gunra affiliates also used credential exposure and SSH access-control weaknesses in VPN gateways. One victim had a default SSL-VPN administrator credential and no account lockout. This means a clean CVE inventory does not clear an exposed gateway whose accounts, sessions, or configuration changed.

Stolen sessions outlive MFA

At one victim, the actors reached an internet-connected administrator workstation, opened the SSL-VPN console, and modified an unused account so it could skip a mandatory password change. They used stolen session material to enter VDI and move through RDP to an authentication server, Active Directory, and IT desktops.

The intrusion then crossed the identity layer. Gunra manipulated VPN traffic to collect credentials and sessions sent to a VDI portal, hijacked session cookies, and changed authentication-processing files so an attacker-selected one-time password would always succeed. The actors also stole an encryption key from a Hiware access-control server and decrypted stored enterprise-server credentials.

The FBI observed secretsdump.py against domain controllers and psexec.py plus smbclient.py for lateral movement. OpenSSH provided tunneling. Those names are dual-use tools, so their presence is a search pivot; process ancestry, account use, command lines, destination systems, and timing establish whether they executed as part of the intrusion.

Gunra commonly worked between 10 p.m. and 6 a.m., deleted access logs, and cleared command history. Hunt privileged gateway, VPN, VDI, RDP, and domain-controller activity together. An isolated alert at any one layer can miss the session and credential chain.

A five-stage flow showing Gunra moving from an exposed edge device through persistence and identity theft into cloud exfiltration, backup deletion, and encryption.

Figure details

Gunra affiliates gain edge access through exploited FortiOS or FortiProxy authentication bypasses, exposed VPN weaknesses, or stolen credentials. They create or alter privileged access, use OpenSSH tunnels, steal sessions and directory credentials, and move through VDI, RDP, and SMB. The actors collect OneDrive, SharePoint, and internal files with main.exe and common archive or transfer tools. Before encryption, they delete shadow copies and backup data. The Windows encryptor appends ENCRT and writes R3ADM3.txt. Verification must cover the edge device, privileged identities, cloud transfers, backup integrity, and endpoint artifacts.

Exfiltration reaches cloud data

The FBI observed a malicious main.exe collecting data from OneDrive and SharePoint. Gunra also used 7-Zip, RClone, FileZilla, and Mega during collection and exfiltration. One victim’s compressed archives reached up to tens of terabytes.

KNPA documented the actors entering IT staff VDI desktops and stealing system and network configuration documents. Credentials taken from the access-control server then enabled ransomware deployment against database servers and network-attached storage. This sequence makes cloud transfer, unusual archive creation, and privileged storage access pre-encryption signals.

The Windows encryptor traverses accessible drive letters from A through Z, skips common system directories and executable file types, and queues user data for parallel ChaCha20 plus RSA-4096 encryption. It appends .ENCRT; one July 2025 sample used .CRYPT. Each encrypted directory receives R3ADM3.txt.

Before encryption, Gunra used this command signature to delete a specific volume shadow copy:

cmd.exe /c C:\Windows\System32\wbem\WMIC.exe shadowcopy where "ID='{guid of shadowcopy}'" delete

The self-contained encryptor can finish without DNS or HTTP traffic. Backup deletion, discovery across many drive letters, high-volume file opens, new .ENCRT files, and R3ADM3.txt are stronger local signals than waiting for a command-server connection.

Gunra leaves exact artifacts

CISA’s complete public-tool hunting set is FileZilla, Amass, RClone, Sliver, 7-Zip, WinRAR, DBeaver, Slack, Microsoft Visual Studio Code, MobaXterm, AnyDesk, Google Remote Desktop, Mimikatz, and the Impacket suite. These applications have legitimate uses. Treat their presence as a hunting lead only when account activity, execution context, destinations, or timing connect them to the intrusion.

CISA marks the network indicators as potentially historical. Vet them against time, ownership, direction, and surrounding activity before blocking:

  • IP addresses: 23.239.119[.]2, 23.239.119[.]3, 23.239.119[.]4, 23.239.119[.]5, 23.239.119[.]6, 86.54.28[.]216, 103.125.234[.]14, 70.36.99[.]82, 211.21.210[.]181, 123.184.143[.]105, 182.204.21[.]240, 182.204.16[.]112, 123.244.187[.]144, 182.204.39[.]118, 67.43.53[.]10, 123.246.37[.]108, and 91.201.66[.]146.
  • Domains: datapub[.]news, gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad[.]onion, lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd[.]onion, and nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd[.]onion.
  • Negotiation email accounts: [email protected], [email protected], [email protected], and [email protected].
  • qTox IDs: 2507312EC10BB44ED9DAA04E3C5C27E8C13154649B1A02E73ACFAE1681EE0208D05133A8FB22, 0FE87CED0C611AE97E049C64288557F49E8271E91399E849328B078DA789A573031783235BEF, 47829AF1C943D4C296C910706923AS199BDA4995B076ED9A9016F7DEF161D445DF00F13E6900, and 9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47.
  • SHA-256 values: 2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751 and 834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1 for main.exe; 91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0 for cryptor.exe; and a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9 for msmp.exe.
  • Endpoint and account markers: forticloud-sync, .ENCRT, .CRYPT, .GNRA, and R3ADM3.txt.

The Linux ELF variant adds a recovery opportunity. CISA says its encryption key uses a predictable srand(time(NULL)) seed. Preserve encrypted files, timestamps, ransom notes, and system logs so responders can attempt mathematical key reconstruction. That weakness does not apply to the Windows encryptor and does not guarantee recovery.

Verify edge, identity, and recovery

Begin with every internet-facing firewall, proxy, VPN, and RDP path. Confirm affected Fortinet branches run at least FortiOS 7.0.17, FortiProxy 7.2.13, or FortiProxy 7.0.20. Where immediate upgrading is impossible, Fortinet recommends disabling HTTP and HTTPS administration or restricting it with local-in policies. The update remains required.

Audit new and altered administrators, jsconsole logins, forticloud-sync, VPN policy changes, session reuse, VDI portal files, unexpected OTP success, domain credential dumping, RDP and SMB movement, OpenSSH tunnels, archive creation, Mega, OneDrive, and SharePoint transfers. Preserve appliance, identity, endpoint, cloud, and backup evidence before eviction.

Test recovery from an immutable, segmented copy that ransomware administrators cannot reach. Verify shadow copies and primary and disaster recovery backups from a clean administrative system.

The expected result is exact: affected edge devices report fixed releases, privileged identity changes have approved owners, no unexplained Gunra pivots remain in retained evidence, cloud transfers match business activity, and a clean restore test succeeds. Any unexplained administrator, session, archive, or backup deletion keeps the response open for containment and scoping.

Primary sources

Continue reading

Article figurePinch or double-tap to zoom, then drag to pan.