Old Code Lives On. New Targets Fall Fast.
# Old Code Lives On. New Targets Fall Fast.
Twenty stories in a single week is not a trend. It's an obsession. Gunra has spent the last seven days dominating my wire, appearing in some 26 separate reports if you count the overlapping aliases. Most ransomware groups prefer to operate in the shadows until the ransom note hits the desktop; Gunra seems content to leave a trail of breadcrumbs that any analyst with a basic grasp of threading could follow.
The most interesting detail isn't who they are hitting, but how they're doing it on Linux systems. According to recent reports, Gunra is utilizing up to 100 ChaCha20 threads to accelerate encryption. For those who don't spend their weekends reading cryptographic primitives, this means they aren't just locking files; they're optimizing for a race against the clock. Most ransomware is surprisingly sloppy with resource management, often choking the CPU and alerting EDR systems through sheer noise. By tuning their threading, Gunra is attempting to finish the job before the security operations center even receives the first alert.
They aren't inventing this from scratch. The playbook here is a scavenger hunt of leaked assets. Gunra is heavily reliant on leaked Conti code and known Fortinet flaws to bypass MFA. There is something profoundly dry about the reality of modern cybercrime: we are seeing "sophisticated" attacks built from a digital surplus store. They're taking the discarded blueprints of a defunct Russian collective and applying them to current infrastructure.
The attribution here is purely probabilistic. The industry loves to draw straight lines from toolsets to nation-states or specific cartels, but that's usually wishful thinking. Because they use leaked Conti code, some analysts will call them a Conti splinter group. Others will see the Fortinet exploits and point toward a broader state-sponsored campaign. I view it as a probability distribution. The likelihood that Gunra is a direct successor to Conti is low; the likelihood that they are simply efficient shoppers who know how to compile leaked C++ is very high.
They've set their sights on governments and critical infrastructure. This aligns with the broader data: Government is currently the #2 most targeted sector, with 246 stories hitting the wire this week alone across all actors. Technology remains at #1 with just under 320 stories. Gunra isn't picking targets based on a grand geopolitical strategy; they're following the path of least resistance in sectors where patching cycles are measured in fiscal quarters rather than hours.
Some will argue that Gunra is merely a "script kiddie" operation scaled up, pointing to their reliance on old flaws and recycled code as evidence of a lack of sophistication. They'll say that without original 0-days, the group isn't a top-tier threat.
That's a fundamental misunderstanding of how the current market works. Innovation in this space isn't about writing new exploits; it's about the weaponization of existing ones. If you can take a leaked codebase and optimize its encryption threads to beat a modern EDR, you've provided more value than a researcher who finds a theoretical bug that no one knows how to trigger. Efficiency is a feature. Speed is a vulnerability.
The second-order effect here isn't the encrypted server—it's the insurance fallout. When Gunra hits critical infrastructure, the immediate concern is uptime. The downstream concern is the underwriters. We're seeing a pattern where the cost of recovery is skyrocketing because the encryption happens so fast that backups are often caught in the blast radius before they can be isolated. If you encrypt 100 threads deep, you aren't leaving much room for a "stop-loss" intervention.
We can see the fragility of this ecosystem elsewhere on the wire. Look at the recent breach affecting just under 14,000 Trezor customers via a shipping partner. It’s the same theme: the perimeter is an illusion. Gunra doesn't need to break your front door if they can find a leaked Fortinet flaw or a neglected service account from a third-party vendor.
The tension lies in the patch gap. We have the fix versions, but we don't have the implementation. For the Fortinet flaws Gunra is leveraging, the patches have existed for some time. The fact that they are still gaining entry suggests that "critical" isn't just a CVSS score; it's a measure of how long a vendor thinks they can ignore a bug before someone like Gunra turns it into a business model.
I suspect we'll see this group shift their threading optimization toward cloud-native environments next. If they've mastered Linux system encryption, the jump to high-throughput cloud storage is trivial. The question isn't whether they can do it, but who is currently running an unpatched Fortinet gateway in a production environment and pretending that MFA is a silver bullet.
If Gunra starts appearing in stories involving SAP Commerce Cloud—which has seen its own set of serious flaws targeted this week—then we're no longer talking about a ransomware gang. We're talking about a systemic collapse of the enterprise middleware layer. I'll be watching the version numbers on those SAP patches very closely.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- Max severity SAP Commerce Cloud flaw now targeted in attacks BleepingComputer
- I went looking for a managed-Postgres provider. Instead, I found a vulnerability in a 4-star PostgreSQL extension available everywhere! and turned it into code execution at NeonDB, Supabase, Xata and many other PostgreSQL service companies r/netsec
- Hackers exploit macOS Screen Sharing flaw to deploy Monero miner BleepingComputer
- Trezor confirms shipping partner data breach affecting over 13,000 customers - SC Media Google News Security
- Data Breach Hits Global Logistics Giant Ceva and Disrupts Operations at Various Warehouses - CPO Magazine Google News Security
- Clop Ransomware Targets Zebra.com in Major Data Breach - DeXpose Google News Security
- ShinyHunters group claims responsibility for RingCentral data breach - SC Media Google News Security
- Cyberattack Wave Leads to French Taxpayer Data Breach - tovima.com Google News Security