Ransomware encryption is usually the last visible act, not the beginning of the incident. By the time a ransom note appears, an operator may already have entered through a remote-access gateway, stolen credentials, crossed into virtual desktops and Active Directory, copied sensitive business data, weakened recovery options, and erased the logs that would explain what happened.
That sequence is the business lesson in the August 10, 2026 joint government advisory #StopRansomware: Gunra Ransomware. The FBI, CISA, Department of Defense Cyber Crime Center, NSA, U.S. Secret Service, and Republic of Korea National Police Agency describe Gunra as a ransomware-as-a-service operation that the FBI first observed in April 2025. Its affiliates use double extortion: steal data first, encrypt systems second, and threaten to publish or sell the stolen information if the victim does not pay. The advisory identifies victims across government, critical infrastructure, healthcare, finance and insurance, manufacturing, transportation, utilities, academia, media, retail, professional services, and nonprofit organizations. [Joint advisory]
Critical readiness message
A successful VPN login or MFA event is not proof that access is legitimate. The Gunra advisory documents stolen sessions, default credentials, and changes to VDI authentication that could make an attacker-controlled one-time password succeed. Treat unexplained edge-administrator changes, VDI authentication-file changes, backup deletion, or confirmed indicators as incident-response triggers—not merely patching tasks.
The 24-Hour Gunra Readiness Checklist
What leadership should require now
- Inventory every internet-facing VPN, firewall, SSL-VPN portal, remote administration interface, VDI gateway, and RDP service, with a named business and technical owner.
- Confirm affected FortiGate and FortiProxy versions are remediated, compare configurations with a trusted baseline, and investigate unknown administrators or scheduled tasks.
- Disable direct internet-facing RDP and restrict necessary remote access through a hardened, monitored path with phishing-resistant MFA where supported.
- Review VDI authentication files, OTP processing, session-cookie use, administrator changes, and off-hours RDP or SMB movement.
- Export VPN, VDI, identity, endpoint, Microsoft 365, backup, DNS, and firewall logs to protected storage before ordinary retention or attacker cleanup destroys them.
- Hunt the official Gunra indicators and behaviors, but validate context before blocking historical IP addresses or dual-use administration tools.
- Prove that at least one recovery copy is offline, immutable, separately administered, segmented, and restorable through a timed clean-room test.
- Pre-authorize who can isolate an edge gateway, VDI system, domain controller, backup plane, subnet, or affected endpoint when incident response finds evidence of active compromise.
This is not an instruction to shut down every remote-access system because Gunra exists. It is a requirement to know which systems are exposed, which controls can be trusted, which evidence exists, and what conditions justify containment before operators reach the encryption phase.
How Gunra Turns Remote Access Into Business Disruption
The FBI observed Gunra affiliates obtaining initial access primarily through known vulnerabilities in internet-facing firewall and VPN appliances. The advisory names two authentication-bypass vulnerabilities affecting certain FortiOS and FortiProxy versions: CVE-2024-55591 and CVE-2025-24472. Fortinet says these flaws may let a remote attacker gain super-administrator privileges through crafted requests and confirms exploitation in the wild. Its minimum fixed releases for the affected branches are FortiOS 7.0.17, FortiProxy 7.2.13, and FortiProxy 7.0.20; organizations should follow Fortinet's current upgrade path rather than treating those minimums as the final destination. [Fortinet PSIRT]
The Korean investigation adds another warning: edge compromise is not always a sophisticated zero-day story. In one victim, operators acquired an SSL-VPN administrator account that still used default credentials and had no account lockout. They downloaded OpenSSH for tunneling and abused an unused dual-homed account after changing its settings to avoid a mandatory password update. Weak credentials, abandoned accounts, missing lockout, and unmanaged remote access can defeat an otherwise expensive security stack.
RDP requires precise treatment. The advisory documents Gunra using RDP for internal lateral movement after gaining access to VDI sessions. It does not make exposed RDP the documented initial-access path in those cases. However, the agencies explicitly tell organizations to prioritize all exposed RDP infrastructure, and the FBI recommends eliminating direct internet-facing RDP. For leaders, the practical conclusion is simple: public RDP is an avoidable entry risk, while internal RDP must be logged, restricted, and segmented because stolen administrative access can turn it into a movement channel. [FBI resiliency guidance]
Edge access
Exploit a known VPN or firewall flaw, reuse exposed credentials, or enter through a weak remote-access account.
Identity and VDI control
Capture credentials or session information, hijack a session, and change authentication processing so MFA appears to succeed.
Quiet expansion
Use RDP, SMB, stolen hashes or tickets, tunnels, and legitimate administration tools to reach servers, IT desktops, and domain controllers.
Data theft and recovery sabotage
Collect business data, move cloud files or archives out, erase logs, delete shadow copies, and attack backup and disaster-recovery data.
Encryption and extortion
Encrypt Windows or Linux systems, issue a ransom demand, and use the threat of leaked data to increase pressure.
Why MFA Can Look Healthy While VDI Is Compromised
In one investigated victim, actors manipulated SSL-VPN traffic controls to capture credentials and VDI session information. They reused stolen cookies to hijack sessions, entered the internal VDI environment, and then moved by RDP to the VDI authentication server, Active Directory, and IT employee desktops. The most important finding for executives was not a failed MFA challenge. It was a successful one that could no longer be trusted.
The actors modified authentication-processing files on the VDI portal so that one attacker-selected one-time password would always work. This was a persistent server-side MFA bypass. An identity dashboard could therefore show an apparently successful second factor while the authentication system itself had been altered. The right investigation compares authentication code and configuration with a known-good baseline, checks file integrity and change history, and correlates the event with device, session-cookie, source network, privilege, and endpoint telemetry.
Review VDI portal files and configuration for unauthorized changes; new or unsigned components; unfamiliar scheduled tasks and services; unexpected local or domain administrators; reused sessions; and logins that do not match the user's device, geography, or work pattern. Also inspect privileged access systems. The advisory documents actors reaching a Hiware access-control server, taking a symmetric key, and decrypting stored enterprise-server passwords. That turns one control-plane compromise into a credential-compromise problem across the environment.
This is where credential hygiene becomes operational resilience. Remove default and dormant accounts, separate remote-access administration from directory administration, use unique privileged credentials, and store recovery material in a managed vault. ITECS is an authorized 1Password reseller and managed services partner, and can incorporate privileged credential separation and lifecycle controls into a broader cybersecurity program. A password manager does not repair a compromised authentication server, but it reduces reuse and makes intentional rotation achievable.
Hunt the Cloud Exfiltration, Not Just the Encryptor
Gunra's double-extortion model means a clean decryptor or successful restore would not erase the breach problem. The FBI observed collection of business-critical documents, databases, personally identifiable information, and internal email. A malicious executable named main.exe was designed to exfiltrate OneDrive and SharePoint data. In one victim environment, operators created compressed archives and transferred up to tens of terabytes to MEGA. The leak site previews generally showed directory listings of exposed OneDrive and SharePoint files, illustrating how file names and folder structures alone can demonstrate damaging access.
Review Microsoft Purview audit data for unusually broad or high-volume activity, including FileDownloaded, FileSyncDownloadedFull, SearchQueryPerformed, anonymous-link creation or use, sharing invitations, changed sharing, and deletion events. Correlate those events with Microsoft Entra interactive and non-interactive sign-ins, service-principal activity, device identity, IP address, application, time, and status. Export the results promptly; audit retention varies by license and policy. [Microsoft audit reference]
Do not assume the victim tenant's audit log will reveal every external destination. If a compromised endpoint or attacker tool uploads data to an attacker-controlled Microsoft 365 tenant or another cloud service, endpoint, browser, sync-client, DNS, proxy, firewall, CASB, and loss prevention telemetry may carry the stronger evidence. Review archive creation, unusual file staging, large egress, unfamiliar cloud clients, and access during the advisory's documented operating window.
The agencies observed malicious activity and internal reconnaissance primarily between 10:00 p.m. and 6:00 a.m. That does not make every late-night administrator malicious or prove that every Gunra lateral move occurs overnight. It does justify higher scrutiny for off-hours remote access, new tunnels, bulk file access, domain-controller queries, RDP, SMB, credential dumping, and backup administration—especially when the account normally works during business hours.
Use IOCs as Leads, Not as a Complete Verdict
Start with the official advisory and its STIX package rather than copying an abbreviated list from another publisher. The indicators include a malicious Fortinet superuser named forticloud-sync; hashes for OneDrive and SharePoint exfiltration tools; ransomware binaries; historical infrastructure; and leak locations. Two SHA-256 values associated with the malicious main.exe are:
2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1
A match should trigger validation, scoping, and incident response. A non-match does not clear the environment because affiliates can change tooling and infrastructure. The advisory also cautions that some IP addresses and domains are historical. Investigate them in context before blocking. Likewise, 7-Zip, Rclone, FileZilla, OpenSSH, PsExec, and other legitimate tools are not malicious by themselves. Their value comes from the surrounding evidence: who launched them, from where, at what time, against which data, using which account, and whether the behavior matches an approved task.
Behavioral findings can be more durable than an IP address: an unexpected FortiGate super-administrator, changes to VDI OTP processing, suspicious session-cookie reuse, unapproved tunnels, secrets-dumping activity against domain controllers, large archive creation, bulk OneDrive or SharePoint access, off-hours RDP and SMB, log deletion, shadow-copy deletion, or access to backup administration.
Preserve Logs Before the Story Disappears
The advisory says Gunra actors deleted system and network access logs and command histories. Log preservation is therefore not a documentation exercise after containment; it is a race against deliberate anti-forensics and ordinary retention limits. When operations permit, preserve evidence before broad patching, rebooting, reimaging, mass credential resets, or configuration replacement changes timestamps and volatile state. If theft or encryption is active, containment takes priority—record every emergency action and its time.
Collect and protect the following:
- Edge systems: FortiGate or other VPN configuration, configuration revisions, administrator changes, scheduled tasks, system events, VPN authentication, traffic, SSH, and session data.
- VDI and identity: portal and authentication-server files, hashes, web and application logs, OTP configuration, session-cookie events, Active Directory changes, domain-controller security logs, privileged access records, and new accounts.
- Endpoints and servers: EDR telemetry, Windows Security, PowerShell, RDP, SMB, WMI, process creation, file creation, archive utilities, tunneling clients, persistence, and command history.
- Cloud and egress: Purview audit exports, Entra sign-ins, OneDrive and SharePoint actions, enterprise application activity, DNS, proxy, firewall, CASB, browser, and sync-client telemetry.
- Recovery systems: backup-console audit logs, policy changes, retention changes, deleted jobs or restore points, backup-administrator sign-ins, storage events, replication, and disaster-recovery access.
Forward these records away from the systems they describe and into protected, ideally immutable storage. The FBI's executive resiliency guidance recommends centralizing authentication, endpoint, network, DNS, remote-access, email, and cloud logs and notes 12 months as a common retention baseline. Your exact retention should reflect incident-response needs, regulation, insurance, cost, and the time required to discover an intrusion. [FBI resiliency guidance]
Backups Are Ready Only After a Clean Restore Test
Gunra targets the assumptions behind recovery. The Windows encryptor deletes volume shadow copies through WMI before encryption. In one victim, the actors deleted backup and archived data in both the primary and disaster-recovery data centers, before and after ransomware deployment. A replicated copy reachable through the same identity and management plane may reproduce an attacker's deletion just as efficiently as it reproduces legitimate changes.
The joint advisory's key action is explicit: implement and test offline, immutable backups stored in a physically separate, segmented location. CISA's broader ransomware guide also calls for offline, encrypted backups and regular restoration testing. [CISA StopRansomware Guide]
A defensible test selects a critical workload, assumes production identity is compromised, restores into an isolated clean environment, scans the restored data, validates application consistency, measures recovery time and data loss, and records every dependency that failed. Use separate backup-administrator accounts and MFA, prevent production administrators from deleting immutable copies, monitor all retention changes and deletion attempts, and keep restore documentation available when the primary network is down. ITECS can help organizations validate this design through backup and disaster recovery services.
When Should Leaders Isolate Systems?
The isolation decision balances two risks: leaving an operator connected long enough to steal or encrypt more, and disconnecting so broadly that responders lose volatile evidence or critical business operations without a recovery path. The advisory says that when compromise is detected before encryption, organizations should identify affected hosts and quarantine or take them offline, begin threat hunting, collect artifacts and logs, and plan eviction after enough evidence is preserved.
| Evidence or condition | Leadership decision |
|---|---|
| Known vulnerable edge appliance, but no evidence of compromise | Restrict exposure, preserve current logs and configuration, apply the vendor upgrade path, rotate affected credentials, and intensify monitoring. |
Unknown edge administrator, forticloud-sync, unauthorized configuration, or unexplained active tunnel |
Treat the appliance as compromised. Preserve configuration and logs, invoke incident response, cut untrusted access, and isolate or replace the gateway using the preplanned alternate-access method. |
| VDI authentication-file modification, universal OTP behavior, session hijacking, or privileged movement | Disable affected authentication paths, revoke sessions, contain implicated VDI and identity systems, and assume reachable credentials require investigation and rotation. |
| Active archive creation, bulk cloud access, or external transfer | Stop the exfiltration path, contain the identity and endpoint, preserve cloud and network evidence, and begin breach-scope and notification analysis. |
| Backup deletion, shadow-copy deletion, widespread lateral movement, or encryption staging | Isolate affected segments immediately, protect the backup plane, invoke executive crisis procedures, and prioritize safety and clean recovery over normal connectivity. |
Pre-authorize the decision now. Name the person who can order isolation after hours, the systems that require a safety or continuity exception, the fallback remote-access method, the incident-response provider, the legal and insurance contacts, and the first restore priorities. If responders must locate executives and debate authority while an operator is deleting backups, the plan has already failed.
Network segmentation should make containment possible without turning off the entire company. Remote-access gateways should not have unrestricted routes to VDI authentication, domain controllers, endpoint management, backup consoles, cloud administration, and production workloads. Use management networks, jump hosts, narrowly allowed protocols, separate administrative identities, and monitoring at each trust boundary. The NSA and CISA describe VPN servers as entry points into protected networks whose compromise can enable credential theft, session hijacking, sensitive-data access, and broader network compromise. [NSA/CISA VPN guidance]
The Decisions to Make Before Encryption Starts
- Choose the isolation authority. Define who can disconnect an appliance, account, server, subnet, or site at 2:00 a.m., and what evidence meets the threshold.
- Choose the minimum viable business. Identify the operations that must continue manually or on isolated systems while the investigation establishes scope.
- Choose the recovery order. Set application dependencies, recovery time and recovery point objectives, clean-room requirements, and the executive owner who accepts restoration risk.
- Choose the evidence standard. Specify which logs are forwarded, how long they are retained, who can place a legal or incident hold, and how collections are documented.
- Choose the credential response. Sequence revocation and rotation for edge administrators, VDI, directory, cloud, service, backup, and application identities so the attacker is removed without locking out responders.
- Choose the communications path. Prepare out-of-band contacts for employees, customers, counsel, cyber insurance, vendors, CISA, the FBI, and other regulators or law enforcement required by the incident.
The FBI does not support paying a ransom, and the joint agencies discourage payment because it does not guarantee recovery or deletion of stolen data and may encourage further crime. That policy decision should still be discussed with counsel, the insurer, and executive leadership before a crisis. The most valuable ransomware decision is the one made early enough that restoration and investigation remain viable options.
If you already have evidence of unauthorized access, log deletion, data staging, backup tampering, or encryption, do not treat this as a routine vulnerability scan. Preserve what you can, stop active harm, and use the ITECS active breach response path or another qualified incident-response team to establish scope.
Can your business contain Gunra before encryption?
ITECS can assess exposed remote access, firewall and VDI controls, identity paths, Microsoft 365 evidence, segmentation, and clean backup restoration before an incident becomes a company-wide outage.
Start a cybersecurity assessment →Related ITECS resources
Sources
- CISA and partners — #StopRansomware: Gunra Ransomware, AA26-222A
- Joint Cybersecurity Advisory PDF — #StopRansomware: Gunra Ransomware
- Fortinet PSIRT — Authentication bypass in Node.js WebSocket module and CSF requests
- CISA, FBI, NSA, and MS-ISAC — #StopRansomware Guide
- FBI — Ten Actions to Improve Cyber Resiliency
- Microsoft Learn — Audit log activities reference
