News Room
16
Share
Gunra Ransomware Surge Triggers Joint US-ROK Advisory as Affiliates Weaponize Leaked Conti Code
criticalThreat Intelligence

Gunra Ransomware Surge Triggers Joint US-ROK Advisory as Affiliates Weaponize Leaked Conti Code

A joint advisory from CISA and South Korea's NPA warns of Gunra ransomware targeting critical infrastructure. The RaaS operation utilizes double-extortion and EDR-blinding techniques to bypass modern defenses.

15 August 2026Last updated 18 August 20265 min readCISA / South Korea National Police Agency
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global (US/South Korea focus)
Confidence:
Confirmed
Source:
CISA / South Korea National Police Agency
Read Time:
5 min

Executive Summary

As of August 15, 2026, the global cybersecurity landscape is facing a significant escalation in ransomware activity, headlined by a joint intelligence advisory from the United States' CISA and South Korea’s National Police Agency (NPA). The advisory, released on August 10, 2026, warns of the Gunra ransomware group, a sophisticated Ransomware-as-a-Service (RaaS) operation that has rapidly expanded its targeting of government agencies and critical infrastructure. This surge coincides with a flurry of other high-profile attacks in the last 48 hours, including breaches by the Everest group against financial entities and SilentRansomGroup targeting U.S. organizations.

Threat Analysis

Gunra emerged in early 2025 but has reached a critical operational maturity in mid-2026. According to The Hacker News, the group is currently exploiting vulnerabilities in Fortinet and Schneider Electric industrial control systems to gain initial access. The group employs a strict double-extortion model, where data is exfiltrated to a dedicated leak site (DLS) before encryption occurs. This trend is mirrored by other active groups; for instance, the Everest group recently claimed responsibility for stealing 186 GB of data from Bolttech and targeting Money Mart on August 11, 2026. Furthermore, the SilentRansomGroup was detected breaching a U.S.-based R&D organization as recently as August 12, 2026.

Technical Details

Gunra’s technical foundation is built upon the leaked source code of the notorious Conti ransomware. However, 2026 variants have been heavily modified to include advanced EDR-blinding capabilities. Intelligence from Infosecurity Magazine indicates that Gunra and similar groups like The Gentlemen are now utilizing 'Bring Your Own Vulnerable Driver' (BYOVD) attacks. By deploying legitimate but vulnerable Windows drivers, attackers can gain kernel-level access to terminate security software processes before the encryption payload is executed. Gunra specifically targets high-severity remote code execution vulnerabilities in Microsoft SharePoint, a flaw CISA confirmed is being actively exploited as of August 11.

Attribution Assessment

While Gunra operates as a RaaS, allowing various affiliates to conduct attacks, the core developers are believed to be remnants of the Conti and Ryuk ecosystems. The joint US-ROK advisory suggests a high degree of coordination among affiliates targeting specific geographic regions, particularly North America and East Asia. The group's ability to commercialize high-end exploits suggests a well-funded operation, likely operating out of jurisdictions that provide safe harbors for cybercriminal activity.

Implications

The 'industrialization' of ransomware in 2026 has shortened the time-to-encrypt significantly. With EDR-kill techniques becoming standard, organizations can no longer rely solely on automated endpoint protection. The targeting of supply chain providers, such as the recent attack on Beacon CRM which impacted the English National Ballet, demonstrates that even small software vendors can serve as gateways to high-value targets.

Recommendations

Encrygma analysts recommend the following immediate actions:

  1. Patch Critical Flaws: Prioritize updates for Microsoft SharePoint (CVE-2026-XXXX) and Fortinet appliances as highlighted in the CISA advisory.
  2. Harden EDR Configurations: Enable tamper protection and implement strict driver blocklists to mitigate BYOVD attacks.
  3. Segment OT/IT: For critical infrastructure providers, ensure robust air-gapping or strict segmentation between industrial control systems and corporate networks.
  4. Enhance Monitoring: Deploy behavioral analytics to detect data exfiltration patterns typical of the Gunra and Everest groups before encryption begins.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo