Find notable cyber news and cases, enriched with sources, timelines, and signals.

Gunra launches RaaS affiliate program and recruits initial access brokers

Threat Actor Meta
First reported
Last updated
Happening score
H score 32
3 unique sources, 3 articles

Summary

Hide ▲

Gunra expanded its criminal operating model in January 2026 by launching a ransomware-as-a-service (RaaS) platform and recruiting initial access brokers. The group also adopted the Golden Community alias while building a more scalable affiliate ecosystem that can widen access to enterprise networks and support extortion operations. The latest advisory ties that same actor to exploitation of CVE-2024-55591 and CVE-2025-24472 in FortiOS/FortiProxy against government and critical infrastructure organizations, with follow-on activity including stolen credentials, MFA bypass, OpenSSH, and exfiltration from Microsoft 365.

Related Happenings

Gunra ransomware CVE exploitation and double-extortion activity

Malware Activity
H score26 First: 10.08.2026 15:00 Last: 10.08.2026 15:00 Sources 1

How related: Gunra ransomware actors are exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organizations, a joint advisory issued by US and Republic of Korea authorities has warned.

About this happening: Gunra ransomware is an RaaS operation targeting government and critical national infrastructure organizations, with a joint US/Republic of Korea advisory warni...

Gunra ransomware mitigation advisory (CISA/FBI/partners)

Advisory/Mitigation
H score26 First: 10.08.2026 15:00 Last: 10.08.2026 15:00 Sources 1

How related: U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks.

About this happening: Gunra ransomware is the focus of a joint advisory from CISA, FBI, DC3, NSA, USSS, and KNPA warning critical infrastructure organizations worldwide. The advisory sa...

UNC6671 diversifies extortion operations across multiple public brands

Threat Actor Meta
H score44 First: 06.08.2026 23:07 Last: 06.08.2026 23:07 Sources 1

About this happening: UNC6671 has shifted to a multi-brand extortion model, widening its operating footprint across Redact, Pink, Helix, and Falcon and increasing the difficulty of tracking...

DevMan-Funky Mantis ecosystem shift changes threat-actor operations

Threat Actor Meta
H score46 First: 25.07.2026 12:53 Last: 25.07.2026 12:53 Sources 1

About this happening: DevMan has consolidated its RaaS affiliate portal, tightening control over payload creation, victim handling, and payouts across its criminal service network. PRODAFT...

ShinyHunters social engineering campaign targeting employee SSO accounts

Campaign
H score77 First: 17.07.2026 23:45 Last: 17.07.2026 23:45 Sources 1

About this happening: The ShinyHunters extortion campaign is using vishing and fake SSO pages to target employee identity accounts, including Microsoft Entra, Okta, and Google SSO...

Timeline

  1. 11.08.2026 12:47 4 articles · 13d ago

    Gunra launches RaaS affiliate program and recruits initial access brokers

    Initial Disclosure

    In January 2026, Gunra shifted to a scalable affiliate model by standing up a RaaS platform. It also started recruiting initial access brokers to broaden access to enterprise targets and support extortion operations.

    Show sources