The FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the US Secret Service and South Korea’s National Police Agency published joint advisory AA26-222A on 10 August 2026, covering the Gunra ransomware.
The advisory dates Gunra to April 2025 and describes it as a double-extortion variant derived from the leaked Conti source code. It became a ransomware-as-a-service operation in January 2026, supplying affiliates with builders and Windows and Linux payloads. Initial access is attributed to CVE-2024-55591 and CVE-2025-24472 in internet-facing devices. Negotiation runs through a Tor portal. Listed target sectors include healthcare, financial services, manufacturing, transport, government, utilities, academia, media, retail and non-profits.
The Conti Leak Keeps Paying Out
Conti took a side over the invasion of Ukraine in early 2022, and someone inside published its chat logs and then its source code. It was read at the time as the end of the operation, and for that brand it was.
What the source release actually did was remove the development cost for everyone who came next. Gunra is one of several descendants, arriving three years later with a working codebase it did not have to write. Publishing an operation’s tooling damages the operation and subsidises its successors, and on the evidence here the second effect runs longer.
Both Entry Vulnerabilities Already Have Fixes
The two CVEs named in the advisory are not zero-days. They are known, numbered and patched, sitting unpatched in internet-facing devices.
That explains the sector list, which reads as a list of everything rather than a strategy. An operation getting in this way does not choose its victims — it takes whoever has not updated.
Read The Signatory List
A cybersecurity agency, a federal law enforcement agency, a defence cyber crime centre, a signals intelligence agency, a protective service and a foreign national police force all signed this.
That is the institutional answer to an operation running on leaked code and unpatched appliances. Advisories are what is available when the operators themselves are out of reach, and their value depends entirely on whether anyone patches after reading one. We have no way to measure that and neither, as far as we can tell, does anyone else.
Compiled from joint advisory AA26-222A and public reporting of it, listed below. The code lineage and CVE attributions are the advisory’s. No victim count, ransom figure or named victim was published. Corrections: corrections@forensicpost.com.