Gunra launches RaaS affiliate program and recruits initial access brokers
Threat Actor Meta
Summary
Hide ▲
Show ▼
Gunra expanded its criminal operating model in January 2026 by launching a ransomware-as-a-service (RaaS) platform and recruiting initial access brokers. The group also adopted the Golden Community alias while building a more scalable affiliate ecosystem that can widen access to enterprise networks and support extortion operations. The latest advisory ties that same actor to exploitation of CVE-2024-55591 and CVE-2025-24472 in FortiOS/FortiProxy against government and critical infrastructure organizations, with follow-on activity including stolen credentials, MFA bypass, OpenSSH, and exfiltration from Microsoft 365.
Related Happenings
Gunra ransomware CVE exploitation and double-extortion activity
Malware Activity
H score26
First: 10.08.2026 15:00
Last: 10.08.2026 15:00
Sources 1
How related:
Gunra ransomware actors are exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organizations, a joint advisory issued by US and Republic of Korea authorities has warned.
About this happening:
Gunra ransomware is an RaaS operation targeting government and critical national infrastructure organizations, with a joint US/Republic of Korea advisory warni...
Gunra ransomware CVE exploitation and double-extortion activity
Malware ActivityHow related: Gunra ransomware actors are exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organizations, a joint advisory issued by US and Republic of Korea authorities has warned.
About this happening: Gunra ransomware is an RaaS operation targeting government and critical national infrastructure organizations, with a joint US/Republic of Korea advisory warni...
Gunra ransomware mitigation advisory (CISA/FBI/partners)
Advisory/Mitigation
H score26
First: 10.08.2026 15:00
Last: 10.08.2026 15:00
Sources 1
How related:
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks.
About this happening:
Gunra ransomware is the focus of a joint advisory from CISA, FBI, DC3, NSA, USSS, and KNPA warning critical infrastructure organizations worldwide. The advisory sa...
Gunra ransomware mitigation advisory (CISA/FBI/partners)
Advisory/MitigationHow related: U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks.
About this happening: Gunra ransomware is the focus of a joint advisory from CISA, FBI, DC3, NSA, USSS, and KNPA warning critical infrastructure organizations worldwide. The advisory sa...
UNC6671 diversifies extortion operations across multiple public brands
Threat Actor Meta
H score44
First: 06.08.2026 23:07
Last: 06.08.2026 23:07
Sources 1
About this happening:
UNC6671 has shifted to a multi-brand extortion model, widening its operating footprint across Redact, Pink, Helix, and Falcon and increasing the difficulty of tracking...
UNC6671 diversifies extortion operations across multiple public brands
Threat Actor MetaAbout this happening: UNC6671 has shifted to a multi-brand extortion model, widening its operating footprint across Redact, Pink, Helix, and Falcon and increasing the difficulty of tracking...
DevMan-Funky Mantis ecosystem shift changes threat-actor operations
Threat Actor Meta
H score46
First: 25.07.2026 12:53
Last: 25.07.2026 12:53
Sources 1
About this happening:
DevMan has consolidated its RaaS affiliate portal, tightening control over payload creation, victim handling, and payouts across its criminal service network. PRODAFT...
DevMan-Funky Mantis ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: DevMan has consolidated its RaaS affiliate portal, tightening control over payload creation, victim handling, and payouts across its criminal service network. PRODAFT...
ShinyHunters social engineering campaign targeting employee SSO accounts
Campaign
H score77
First: 17.07.2026 23:45
Last: 17.07.2026 23:45
Sources 1
About this happening:
The ShinyHunters extortion campaign is using vishing and fake SSO pages to target employee identity accounts, including Microsoft Entra, Okta, and Google SSO...
ShinyHunters social engineering campaign targeting employee SSO accounts
CampaignAbout this happening: The ShinyHunters extortion campaign is using vishing and fake SSO pages to target employee identity accounts, including Microsoft Entra, Okta, and Google SSO...
Timeline
-
11.08.2026 12:47 4 articles · 13d ago
Gunra launches RaaS affiliate program and recruits initial access brokers
Initial DisclosureIn January 2026, Gunra shifted to a scalable affiliate model by standing up a RaaS platform. It also started recruiting initial access brokers to broaden access to enterprise targets and support extortion operations.
Show sources
- US and South Korea warn of Gunra ransomware targeting govt agencies — www.bleepingcomputer.com — 11.08.2026 12:47
- US and South Korea warn of Gunra ransomware targeting govt agencies — www.bleepingcomputer.com — 11.08.2026 12:47
- Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks — thehackernews.com — 11.08.2026 12:16
- Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure — www.infosecurity-magazine.com — 12.08.2026 16:15