Threat Advisory: VibeCoded Malware Targeting Active Directory Services
AI-generated PowerShell scripts are evading signature-based detection in live Active Directory attacks. See what UltraViolet TIDE found and how to respond.
Find flaws in AI Systems
Find flaws in web, mobile, and IoT applications.
Live-fire exercises to sharpen detection and response.
Time-boxed security assessments across networks, apps, and infrastructure.
Simulated attacks to test detection and incident response.
Named security experts integrated seamlessly into your team.
Real-time detection and automated threat response.
24x7 monitoring and response by expert analysts.
Detection-focused SIEM migration without visibility gaps.
UltraViolet's proprietary AI platform powering all application penetration testing.
Unified security platform powering all UV services.
Cross-platform toolkit for advanced red team ops.
UltraViolet Cyber provides security services across the AI lifecycle, combining strategy, threat modeling, adversarial testing, monitoring, and training to support secure AI adoption.
Learn how a major U.S. airport operator achieved 24/7 threat detection, improved security maturity, and ...
Secure your code, infrastructure, and deployment pipelines before attackers exploit them.
Six TIDE advisories in six weeks point to the same gaps: unmanaged AI infrastructure, signature-based detection, and ...
AI Governance by DesignAn Architecture-Aware Approach for Embedding Governance into AI Systems
UltraViolet Cyber is a practitioner-led MSSP delivering offensive and defensive security to Global 2000 and Federal clients. Built by former intelligence operators, we unify application security, red teaming, detection, and engineering under one roof. Our UV Lens platform replaces silos with integrated, outcome-driven operations.
UltraViolet Cyber
August 12, 2026
CISA, the FBI, NSA, DC3, the U.S. Secret Service, and South Korea's National Police Agency issued a joint advisory this week warning that Gunra ransomware actors are actively targeting critical infrastructure worldwide. Gunra is a double-extortion ransomware-as-a-service operation built on leaked Conti source code that first appeared in spring 2025 and has since expanded into a structured affiliate program recruiting financially motivated criminals through dark web forums.
The group primarily gains initial access by exploiting two long-known Fortinet FortiOS/FortiProxy authentication bypass flaws, both of which have sat in CISA's Known Exploited Vulnerabilities catalog for over a year yet remain unpatched at many organizations. Once inside, affiliates hijack VPN and virtual desktop infrastructure, defeat multi-factor authentication, and combine data theft with encryption before threatening public leaks.
What UltraViolet Cyber is Doing
ADVERSARY PROFILE
Golden Community
ALSO
GUNRA, Gunra Ransomware Group
ATTRIBUTION
Unattributed, not attributed to a specific agency or unit
ACTIVE SINCE
2025 (1+ years)
MOTIVES
Financial gain, data extortion
INDUSTRIES
Healthcare and public health, financial services, government services and facilities, manufacturing, and professional and nonprofit services.
COUNTRIES
South Korea, Brazil, Spain, Thailand, and Hong Kong.
Notable TTPs
Gunra represents a maturing ransomware-as-a-service model that lowers the technical bar for affiliates while still achieving sophisticated outcomes against hardened targets. Built on Conti's leaked codebase, the malware supports both Windows and Linux payloads and uses fast stream ciphers capable of encrypting very large datasets quickly. Since formalizing its affiliate program in early 2026, Gunra has provided partners with a management console, a configurable builder, and structured documentation, functionally commoditizing ransomware deployment for less experienced criminals.
Gunra follows a double-extortion model, meaning affiliates both steal a victim's data and encrypt their systems. This gives them two separate points of leverage: victims face operational disruption from encrypted files and the threat of stolen data being published on a leak site if payment isn't made within five to seven days, even if they can restore from backup.
The group's initial access technique relies on patching gaps rather than novel exploitation. CVE-2024-55591 is a critical authentication bypass flaw in FortiOS and FortiProxy that grants attackers super-admin privileges on affected devices, while CVE-2025-24472 is a related high-severity authentication bypass impacting the same products. Both vulnerabilities were disclosed and patched over a year ago, yet Gunra continues to find unpatched, internet-facing instances still exposed.
What distinguishes Gunra operationally is its systematic targeting of identity infrastructure. Affiliates have manipulated SSL-VPN traffic-control features to intercept credentials and session cookies from users authenticating to a corporate VDI portal, then used those stolen sessions to impersonate legitimate users. In at least one case, they altered authentication-processing files so a Gunra-chosen one-time password value would always succeed, neutralizing MFA rather than bypassing it just once.
Additional tradecraft includes exploiting default or dormant administrative accounts, harvesting a symmetric encryption key from an access-control server to decrypt stored enterprise credentials, and using Impacket utilities for SMB-based lateral movement and credential dumping. The group operates mainly overnight, clears logs and command history, exfiltrates data via a custom executable and the MEGA file-sharing service, and deletes backups at both primary and disaster-recovery sites before and after encryption.
This activity matters because it shows patch debt on perimeter devices, not novel exploits, is driving major ransomware losses against critical infrastructure. Both Fortinet vulnerabilities were disclosed and patched over a year ago, yet they are still yielding successful intrusions today. This gap underscores that vulnerability management and asset visibility, especially for internet-facing appliances like VPNs and firewalls, remain a primary enabler for well-resourced RaaS operations. It also signals that attackers don't need zero-days to succeed; they simply need organizations to be slow to patch. For stakeholders, this reframes "known" vulnerabilities as an ongoing operational risk rather than a solved problem once a patch exists.
The MFA-bypass technique is especially significant because it undermines a control many organizations treat as a definitive safeguard. If authentication files on VDI or SSL-VPN portals can be silently modified so that attacker-chosen credentials are always accepted, MFA alone cannot be assumed to stop account takeover. This matters to stakeholders because breach notification obligations, cyber insurance terms, and customer assurances often lean heavily on the presence of MFA as evidence of due diligence. Gunra's approach shows that the mere existence of MFA doesn't guarantee its integrity, which has implications for how confidently organizations and their boards can rely on that control during risk assessments or after an incident.
The systematic deletion of backups before and after encryption also raises the stakes for business continuity and disaster recovery planning. By deliberately targeting both primary and disaster-recovery backup locations, Gunra affiliates aim to remove the safety net organizations rely on to avoid paying ransoms or enduring prolonged outages. This directly affects recovery time objectives, insurance claims, and the overall calculus victims face when deciding whether to negotiate. Stakeholders responsible for continuity planning should recognize that backup availability can no longer be assumed once an intrusion has occurred undetected for any length of time.
Finally, while Gunra's victim base has skewed heavily toward Asia-Pacific, South America, and Europe so far, with only a small number of confirmed North American victims, the sector spread, healthcare, financial services, government, and manufacturing, shows a targeting model that is opportunistic rather than tied to any single region. Combined with a growing affiliate program actively recruiting new operators, this suggests North American organizations should not read the current victim geography as a reason for complacency. This carries direct implications for operational continuity, regulatory reporting obligations, and public safety, particularly for healthcare and government entities where service disruption can affect the public directly rather than just the organization's bottom line.
We’re here to help. Get in touch for an initial conversation with one of our security experts and learn more about how UltraViolet Cyber can help you take cyber readiness and resilience to new levels.