
Gunra and Blacknevas Ransomware Escalation: Critical Infrastructure Under Siege via Fortinet and SharePoint Flaws
A joint international advisory warns of a surge in Gunra ransomware activity targeting critical infrastructure. Simultaneously, the Blacknevas and SilentRansomGroup actors have intensified double-extortion campaigns against U.S. and Canadian financial entities.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2024-55591, CVE-2025-24472
- Source:
- CISA / FBI / South Korea NPA
- Read Time:
- 5 min
Executive Summary
As of August 15, 2026, Encrygma intelligence monitors a significant escalation in ransomware operations targeting global critical infrastructure. A joint advisory released by CISA, the FBI, and South Korea’s National Police Agency (NPA) has identified the Gunra ransomware group as a primary threat actor. Gunra, a Ransomware-as-a-Service (RaaS) operation, has transitioned from a niche variant to a major industrialized threat, leveraging a double-extortion model to pressure victims in the healthcare, financial, and government sectors. This surge coincides with active exploitation of legacy and zero-day vulnerabilities in edge devices and collaboration platforms, alongside fresh victim disclosures from the Blacknevas and SilentRansomGroup syndicates.
Threat Analysis
Gunra first emerged in early 2025 but has recently refined its operational tempo. The group utilizes a double-extortion strategy, exfiltrating sensitive data to a dedicated leak site (DLS) before deploying encryption. Intelligence indicates that Gunra is actively recruiting experienced penetration testers to enhance its initial access capabilities. In parallel, the Blacknevas group has claimed five new victims in the last 72 hours, including major financial service providers in North America, signaling a shift toward high-value, data-rich targets. These groups are increasingly moving away from simple encryption toward 'extortion-only' or 'EDR-blinding' tactics to ensure maximum leverage over their victims.
Technical Details
The current wave of attacks relies heavily on the exploitation of internet-facing vulnerabilities. Gunra affiliates have been observed weaponizing CVE-2024-55591 and CVE-2025-24472, which affect Fortinet FortiOS and FortiProxy systems. These flaws allow for unauthorized remote code execution (RCE), providing a foothold for lateral movement. Furthermore, CISA has confirmed that ransomware actors are now exploiting a high-severity Microsoft SharePoint RCE vulnerability to bypass traditional perimeter defenses. Once inside, actors deploy 'EDR-kill' scripts—a technique recently popularized by 'The Gentlemen' ransomware group—to disable security monitoring before the final payload is executed. In the case of Gunra, the ransomware variant is built upon leaked Conti source code, though it has been heavily modified to include a Linux-based variant targeting ESXi environments.
Attribution Assessment
Gunra is assessed with high confidence to be a financially motivated cybercriminal syndicate, likely operating out of Eastern Europe given its reliance on Conti-based code and recruitment patterns on Russian-language underground forums. The group’s collaboration with South Korean-based affiliates suggests a globalized RaaS structure. The SilentRansomGroup, which hit a U.S. organization on August 12, 2026, appears to be a splinter cell of earlier Lapsus$ or Conti affiliates, focusing on credential theft and social engineering to bypass Multi-Factor Authentication (MFA).
Implications
The targeting of critical infrastructure—specifically healthcare and government facilities—poses a direct threat to public safety and national security. The industrialization of these attacks, where vulnerabilities are exploited within days of discovery, leaves organizations with a shrinking window for remediation. The success of the Gunra and Blacknevas campaigns will likely embolden other RaaS groups to adopt similar 'supply-chain-first' mentalities, targeting software providers like Beacon CRM to gain access to downstream clients.
Recommendations
Encrygma recommends that organizations immediately prioritize the patching of all Fortinet and Microsoft SharePoint instances. Implementation of robust EDR solutions with tamper-protection is critical to counter 'EDR-blinding' scripts. Furthermore, organizations should adopt a zero-trust architecture to limit lateral movement and ensure that all sensitive data is encrypted at rest, reducing the impact of double-extortion tactics. Regular, offline backups remain the most effective defense against total operational shutdown.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors

Ransomware Surge: Emperador and SafePay Lead Record-Breaking September 2026 Extortion Wave

