Circuit Wire — a daily news update from the Circuit.
The FBI, CISA, the NSA, the Secret Service, the Pentagon's Cyber Crime Center and South Korea's National Police Agency published a joint advisory on Gunra ransomware on August 10, mapping how the group breaks into networks across ten sectors, including healthcare, financial services, transportation, utilities and government.
Gunra first appeared in April 2025, built on the Conti source code leaked in 2022. By early this year it had grown into a ransomware-as-a-service operation, advertising an affiliate program on dark web forums under the alias Golden Community and recruiting penetration testers to act as initial access brokers in exchange for a share of ransom profits. Affiliates get a management panel, a configurable builder and both Windows and Linux encryptors.
The group typically gets in by exploiting known flaws in internet-facing firewall and VPN appliances, including two Fortinet authentication bypass vulnerabilities, CVE-2024-55591 and CVE-2025-24472. From there the advisory documents a methodical playbook. In one case, actors modified a victim's authentication server so that a single attacker-chosen one-time passcode always worked, creating a persistent backdoor around multi-factor authentication. Investigators also observed the group sniffing VPN traffic to steal login sessions, dumping credentials from domain controllers, and timing its activity between 10 p.m. and 6 a.m. to avoid detection.
The impact model is standard double extortion, executed thoroughly. Actors exfiltrated up to tens of terabytes per victim to the file-sharing service Mega before encrypting systems, and in one case deleted backups at both the victim's primary data center and its disaster recovery site. Ransom notes direct victims to a Tor negotiation portal, with opening demands that the FBI says often exceed tens of millions of dollars and a five-to-seven-day deadline before data is published on the group's leak site.
The advisory carries one piece of good news. Researchers found in March that the Linux variant's encryption keys come from a weak random number generator seeded with the system clock, which means defenders can reconstruct the keys from file timestamps and recover encrypted files without paying. The authoring agencies urge victims to preserve encrypted files, timestamps and ransom notes for that reason.
The recommended defenses will look familiar: patch known exploited vulnerabilities on internet-facing systems first, keep offline and immutable backups in a physically separate location, segment networks to limit lateral movement, and require multi-factor authentication for VPNs and webmail. The Record reported that at least four ransomware attacks on industrial organizations last quarter were attributed to Gunra, citing figures from the cybersecurity firm Dragos. The advisory also lands after a run of exploited remote-access flaws in Progress LoadMaster, N-able N-central and SonicWall devices that we covered over the past two weeks.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

