CISA and FBI Detail Defense Playbook Against 'Gunra' Critical Infrastructure Ransomware
A joint cybersecurity advisory outlines how the Gunra ransomware syndicate exploits perimeter vulnerabilities, while revealing a cryptographic flaw that allows some victims to recover data for free.
By Wei Zhang
The cybersecurity industry often treats ransomware syndicates as omnipotent, sophisticated adversaries capable of breaching any enterprise defense with untraceable zero-day exploits. But a new joint advisory from United States and South Korean intelligence agencies reveals that the groups behind the latest wave of critical infrastructure attacks are heavily relying on basic perimeter negligence—and in some cases, deploying flawed malware that hands the decryption keys right back to the victim. The release serves as a rare moment of optimism for network defenders, shifting the narrative from inevitable compromise to actionable prevention.[1]
On August 10, the Federal Bureau of Investigation, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency, and South Korea’s National Police Agency released a comprehensive playbook on a threat actor known as Gunra. The ransomware-as-a-service operation first emerged in April 2025, reportedly built on the leaked source code of the defunct Conti gang. Since its inception, the syndicate has aggressively targeted the government, healthcare, financial services, and manufacturing sectors across the globe, prompting the coordinated international response to dissect its methods and provide a blueprint for defense.[1][3]
While the group heavily markets itself as a sophisticated double-extortion operation on dark web forums—promising its criminal affiliates an alluring 80 percent cut of the extortion profits—the reality of their network intrusions is far more mundane. Gunra does not typically rely on expensive zero-day exploits or novel hacking techniques to breach a perimeter. Instead, affiliates gain their initial access by continuously scanning the internet for unpatched Fortinet virtual private network and firewall appliances, specifically exploiting two known authentication bypass vulnerabilities designated as CVE-2024-55591 and CVE-2025-24472.[2][5]
Once inside the target network, the attackers drop the sophisticated hacker facade and rely almost entirely on standard IT administrative tools to navigate the environment. The joint advisory notes that Gunra affiliates frequently use Impacket’s standard scripts, such as psexec.py and smbclient.py, to move laterally across the network and access file servers. From the perspective of the enterprise storage system, the malicious actor appears as just another authenticated employee session, browsing network shares and reading files over the standard Server Message Block protocol.[4]
Before any encryption software is deployed, the attackers conduct a sustained, credentialed bulk read of unstructured data across the organization. They methodically scrape business-critical documents, proprietary databases, personally identifiable information, and internal email communications, often exfiltrating tens of terabytes of sensitive data to commercial cloud storage services like Mega and OneDrive. This massive data theft forms the foundation of their double-extortion business model: victims are forced to pay the ransom not just to unlock their systems, but to prevent their private data from being published on a Tor-based leak site.[1][2]
However, the most significant and empowering revelation in the government advisory is a catastrophic error in Gunra’s own Linux encryption software. Security analysts and incident responders discovered that the Linux variant of the malware seeds its random number generator using the local system time of the infected machine. This fundamental cryptographic flaw means that the resulting encryption key is entirely predictable, provided that network defenders can accurately reconstruct the exact timestamp of when the encryption attack was executed.[6]
For incident response teams, this cryptographic vulnerability transforms a potential operational disaster into a manageable recovery scenario. If IT personnel preserve the encrypted files, the ransom notes, and the system logs rather than immediately wiping the compromised Linux machines in a panic, specialists can reverse-engineer the encryption key. This allows the victim organization to decrypt their files entirely for free, completely bypassing the extortion demand and denying the syndicate their primary leverage.[1][6]
The advisory also highlights the devastating consequences of poor backup architecture, serving as a cautionary tale for enterprise administrators. In one documented incident, Gunra actors managed to wipe backup and archived data at both the victim’s primary and disaster recovery data centers. The attackers accomplished this total destruction not through advanced hacking, but by stealing a single cryptographic key from a central access-control server that subsequently decrypted the stored passwords for every enterprise server in the network.[1]
Defending against the Gunra syndicate, the intelligence agencies emphasize, does not require next-generation artificial intelligence tools or expensive new security platforms. It requires a strict adherence to fundamental IT hygiene and architectural best practices.
The primary mitigations outlined in the playbook include immediately patching internet-facing Fortinet appliances, implementing offline immutable backups that cannot be reached or altered from the primary network, and strictly segmenting networks to restrict lateral movement. By treating data storage as a primary defensive layer, organizations can detect the bulk exfiltration of files before the encryption phase even begins.[1][3]
By demystifying the syndicate’s tactics and exposing their cryptographic blunders, the joint advisory shifts the balance of power back to network defenders. It strips away the intimidating marketing hype of the ransomware-as-a-service ecosystem, revealing a threat actor that is highly opportunistic but fundamentally reliant on the basic security failures of its victims. For critical infrastructure operators, the message is clear: the tools to defeat these extortionists are already in their hands, provided they configure their networks to use them.[1][4]
Key points
- A joint advisory from U.S. and South Korean agencies details the tactics of the Gunra ransomware-as-a-service operation.
- Gunra affiliates gain initial access by exploiting known vulnerabilities in Fortinet VPN and firewall appliances.
- The attackers use standard IT administrative tools to scrape unstructured data before deploying encryption.
- A critical cryptographic flaw in Gunra's Linux encryptor allows defenders to recover files for free if system timestamps are preserved.
- Federal Cybersecurity Agencies
- Focus on perimeter patching and immutable backups to prevent initial access and ensure recovery.
- Storage and Infrastructure Defenders
- Advocate for data-layer behavioral analytics to catch credentialed lateral movement and exfiltration.
- Incident Response Specialists
- Prioritize evidence preservation to exploit malware flaws and avoid ransom payments.
Perspectives this story doesn't cover
- Gunra Ransomware Affiliates
- Compromised Organizations
Sources
[1]Cybersecurity and Infrastructure Security AgencyFederal Cybersecurity Agencies#StopRansomware: Gunra Ransomware
Read on Cybersecurity and Infrastructure Security Agency →
[2]Infosecurity MagazineStorage and Infrastructure DefendersGunra Ransomware Actors Target Critical Infrastructure via Fortinet Flaws
Read on Infosecurity Magazine →
[3]Homeland Security TodayFederal Cybersecurity AgenciesCISA, FBI Warn Gunra Ransomware Actors Targeting Critical Infrastructure
Read on Homeland Security Today →
[4]RackTop SystemsStorage and Infrastructure DefendersGunra ransomware: a six-agency warning that ends at your file shares
Read on RackTop Systems →
[5]Dark ReadingIncident Response SpecialistsGunra Ransomware Exploits Known Vulnerabilities in Critical Infrastructure Campaigns
Read on Dark Reading →
[6]CybelAngelIncident Response SpecialistsGunra Ransomware Targets Critical Infrastructure
Read on CybelAngel →
More in Technology
See all →OAuth 2.0
The Six Steps of the OAuth 2.0 Authorization Code Flow with PKCE
4 sources
Core Vulnerability
WordPress Patches Critical Core Vulnerability as Attackers Exploit Flaw Within Hours
5 sources
Zero-Day Exploits
Chinese State-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
4 sources
Maritime Security
FBI and Coast Guard Board US-Bound Oil Tankers Following Suspected Cyberattacks
5 sources
Comments
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns, free every day.




