A joint cybersecurity advisory from the FBI, CISA, Department of Defense Cyber Crime Center, NSA, U.S. Gunra first surfaced in April 2025 as a double-extortion ransomware strain based on leaked Conti source code. The FBI also observed the group rebranding under the alias Golden Community while actively recruiting penetration testers and ethical hackers as initial access brokers in exchange for a cut of ransom profits. In one instance, attackers compromised an SSL-VPN administrator account using default credentials without any lockout controls, then modified the authentication files on a corporate VDI portal to always authenticate successfully with a designated one-time password value.
Victims are directed toward a Tor-based negotiation portal or the encrypted messaging app qTox, typically given five to seven days before Gunra threatens to leak or sell stolen data on its dedicated leak site. The advisory urges organizations, particularly those in healthcare, financial services, critical manufacturing, transportation, and government sectors, to prioritize patching internet-facing VPN and RDP infrastructure, maintaining offline and immutable backups in segmented locations, and enforcing network segmentation to contain lateral movement. Given Gunra's proven capability to bypass MFA through authentication file tampering, security teams should also review VPN and VDI authentication logic for unauthorized modifications and monitor for known Gunra-linked IP addresses, domains, and file hashes listed in the CISA advisory's indicators of compromise.












