
Gunra Ransomware Surge Triggers Joint US-ROK Advisory as Affiliates Weaponize Leaked Conti Code
A joint advisory from CISA and South Korea's NPA warns of Gunra ransomware targeting critical infrastructure. The RaaS operation utilizes double-extortion and EDR-blinding techniques to bypass modern defenses.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global (US/South Korea focus)
- Confidence:
- Confirmed
- Source:
- CISA / South Korea National Police Agency
- Read Time:
- 5 min
Executive Summary
As of August 15, 2026, the global cybersecurity landscape is facing a significant escalation in ransomware activity, headlined by a joint intelligence advisory from the United States' CISA and South Korea’s National Police Agency (NPA). The advisory, released on August 10, 2026, warns of the Gunra ransomware group, a sophisticated Ransomware-as-a-Service (RaaS) operation that has rapidly expanded its targeting of government agencies and critical infrastructure. This surge coincides with a flurry of other high-profile attacks in the last 48 hours, including breaches by the Everest group against financial entities and SilentRansomGroup targeting U.S. organizations.
Threat Analysis
Gunra emerged in early 2025 but has reached a critical operational maturity in mid-2026. According to The Hacker News, the group is currently exploiting vulnerabilities in Fortinet and Schneider Electric industrial control systems to gain initial access. The group employs a strict double-extortion model, where data is exfiltrated to a dedicated leak site (DLS) before encryption occurs. This trend is mirrored by other active groups; for instance, the Everest group recently claimed responsibility for stealing 186 GB of data from Bolttech and targeting Money Mart on August 11, 2026. Furthermore, the SilentRansomGroup was detected breaching a U.S.-based R&D organization as recently as August 12, 2026.
Technical Details
Gunra’s technical foundation is built upon the leaked source code of the notorious Conti ransomware. However, 2026 variants have been heavily modified to include advanced EDR-blinding capabilities. Intelligence from Infosecurity Magazine indicates that Gunra and similar groups like The Gentlemen are now utilizing 'Bring Your Own Vulnerable Driver' (BYOVD) attacks. By deploying legitimate but vulnerable Windows drivers, attackers can gain kernel-level access to terminate security software processes before the encryption payload is executed. Gunra specifically targets high-severity remote code execution vulnerabilities in Microsoft SharePoint, a flaw CISA confirmed is being actively exploited as of August 11.
Attribution Assessment
While Gunra operates as a RaaS, allowing various affiliates to conduct attacks, the core developers are believed to be remnants of the Conti and Ryuk ecosystems. The joint US-ROK advisory suggests a high degree of coordination among affiliates targeting specific geographic regions, particularly North America and East Asia. The group's ability to commercialize high-end exploits suggests a well-funded operation, likely operating out of jurisdictions that provide safe harbors for cybercriminal activity.
Implications
The 'industrialization' of ransomware in 2026 has shortened the time-to-encrypt significantly. With EDR-kill techniques becoming standard, organizations can no longer rely solely on automated endpoint protection. The targeting of supply chain providers, such as the recent attack on Beacon CRM which impacted the English National Ballet, demonstrates that even small software vendors can serve as gateways to high-value targets.
Recommendations
Encrygma analysts recommend the following immediate actions:
- Patch Critical Flaws: Prioritize updates for Microsoft SharePoint (CVE-2026-XXXX) and Fortinet appliances as highlighted in the CISA advisory.
- Harden EDR Configurations: Enable tamper protection and implement strict driver blocklists to mitigate BYOVD attacks.
- Segment OT/IT: For critical infrastructure providers, ensure robust air-gapping or strict segmentation between industrial control systems and corporate networks.
- Enhance Monitoring: Deploy behavioral analytics to detect data exfiltration patterns typical of the Gunra and Everest groups before encryption begins.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors

Ransomware Surge: Emperador and SafePay Lead Record-Breaking September 2026 Extortion Wave

