Desk live·
ForensicPost
Ransomware/Method/File 26-0810

Six Agencies Warn Gunra Ransomware Runs on Leaked Conti Source Code

A joint advisory from the FBI, CISA, NSA and three other agencies describes Gunra as a double-extortion operation built from Conti’s leaked source, now running as a service and getting in through two vulnerabilities that already have patches.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetMultiple critical infrastructure sectors
ActorGunra
D. Kennedy10 min readConfidence: high3 sources reviewed

The FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the US Secret Service and South Korea’s National Police Agency published joint advisory AA26-222A on 10 August 2026, covering the Gunra ransomware.

The advisory dates Gunra to April 2025 and describes it as a double-extortion variant derived from the leaked Conti source code. It became a ransomware-as-a-service operation in January 2026, supplying affiliates with builders and Windows and Linux payloads. Initial access is attributed to CVE-2024-55591 and CVE-2025-24472 in internet-facing devices. Negotiation runs through a Tor portal. Listed target sectors include healthcare, financial services, manufacturing, transport, government, utilities, academia, media, retail and non-profits.

The Conti Leak Keeps Paying Out

Conti took a side over the invasion of Ukraine in early 2022, and someone inside published its chat logs and then its source code. It was read at the time as the end of the operation, and for that brand it was.

What the source release actually did was remove the development cost for everyone who came next. Gunra is one of several descendants, arriving three years later with a working codebase it did not have to write. Publishing an operation’s tooling damages the operation and subsidises its successors, and on the evidence here the second effect runs longer.

Both Entry Vulnerabilities Already Have Fixes

The two CVEs named in the advisory are not zero-days. They are known, numbered and patched, sitting unpatched in internet-facing devices.

That explains the sector list, which reads as a list of everything rather than a strategy. An operation getting in this way does not choose its victims — it takes whoever has not updated.

Read The Signatory List

A cybersecurity agency, a federal law enforcement agency, a defence cyber crime centre, a signals intelligence agency, a protective service and a foreign national police force all signed this.

That is the institutional answer to an operation running on leaked code and unpatched appliances. Advisories are what is available when the operators themselves are out of reach, and their value depends entirely on whether anyone patches after reading one. We have no way to measure that and neither, as far as we can tell, does anyone else.

How we reported this

Compiled from joint advisory AA26-222A and public reporting of it, listed below. The code lineage and CVE attributions are the advisory’s. No victim count, ransom figure or named victim was published. Corrections: corrections@forensicpost.com.

Sources
  1. #StopRansomware: Gunra Ransomware (AA26-222A)CISA
  2. Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructureThe Register
  3. CISA, FBI Warn Gunra Ransomware Actors Targeting Critical InfrastructureHSToday
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary