The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

What Gunra tells us about our perimeter

The Perimeter Desk
2026-08-18
# What Gunra tells us about our perimeter If you run a ten-person shop, you don't have the luxury of caring about the nuance of threat actor naming conventions. Whether they call themselves Gunra, Akira, or "Group 123" doesn't change the fact that they want your data and your money. But this week, Gunra is the one making enough noise to warrant a look, specifically because their playbook targets the exact things small businesses tend to ignore until it's too late. Gunra isn't reinventing the wheel. They are scavengers. Much of their success comes from leveraging leaked Conti code and exploiting old flaws in Fortinet gear. They aren't using some zero-day magic found in a basement in Pyongyang; they're walking through doors that were left unlocked three years ago. The most alarming part of the Gunra toolkit is their speed. They use up to 100 ChaCha20 threads to encrypt Linux systems. For those who aren't system administrators, this means they aren't just locking a few files here and there. They are saturating the CPU to shred your entire server in minutes. By the time you notice your website is down or your database is unresponsive, the encryption process is likely already finished. The attribution here is probable, not certain. The industry likes to slap a label on a group based on code overlaps, but in reality, Gunra is likely a Ransomware-as-a-Service (RaaS) operation. They are essentially franchisees using a proven business model. The "who" matters less than the "how." They get in through the perimeter. Specifically, they're hitting Fortinet vulnerabilities and bypassing MFA. This is where I’ll take a hard line: if you believe that clicking "Enable MFA" on your VPN makes you unhackable, you are dangerously wrong. MFA is a hurdle, not a wall. If the underlying firmware on your firewall has a hole in it, an attacker can often bypass the authentication layer entirely. An enterprise with a twenty-million-dollar security budget handles this by having a dedicated team monitor for "anomalous lateral movement" and using expensive EDR tools that flag weird CPU spikes. A small firm doesn't have a SOC. You have a guy named Dave who does IT on the side. For you, the cost of defense isn't a monthly subscription to a fancy dashboard; it's the discipline to run firmware updates every single time they drop. There is also a second-order effect here that most small business owners miss. You might not use Fortinet, but your managed service provider (MSP) probably does. If Gunra hits an MSP, they aren't just hitting one company; they're getting a roadmap to fifty different small businesses through a single set of administrative credentials. We saw this pattern before with Kaseya and others. The risk isn't just in your own closet—it's in the keys you've handed to your vendors. Some will argue that patching every piece of gear immediately is unrealistic because it causes downtime. "I can't take my VPN offline for twenty minutes on a Tuesday," they say. My answer is simple: you can either take it offline for twenty minutes now, or you can take it offline for two weeks while you try to recover from backups that might not even work. The scale of the current climate is obvious if you look at the wreckage. Just this week, we've seen a breach at MyDr potentially exposing just under 19 million people and another hit at Heights Finance affecting north of 735,000 customers. While Gunra might not be hitting those specific targets yet, they are operating in an environment where data is the primary currency and speed is the primary weapon. The cost difference here is stark. An enterprise spends hundreds of thousands on "threat hunting" to find an actor like Gunra before they encrypt. A small business can achieve 80% of that protection for free by simply ensuring their perimeter gear isn't running software from 2023 and that their backups are stored off-site and offline. If you rely on a cloud provider, remember that "the cloud" is just someone else's computer. If that computer is running an unpatched Linux kernel and Gunra finds the door, your MFA won't save you. Check the firmware version on your edge firewall this week.
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More The Hacker News
  2. Heights Finance Data Breach Impacts at Least 1.2 Million Individuals SecurityWeek
  3. Apple Screen Sharing Security, (Mon, Aug 17th) SANS ISC
  4. Poland probes MyDr healthcare software breach potentially affecting 19 million people The Record
  5. Critical flaw in SAP Commerce Cloud faces initial exploitation attempts - Cybersecurity Dive Google News Security
  6. Microsoft confirms GitHub is down worldwide BleepingComputer
  7. Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach The Record
  8. CISA: Windows Task Host flaw now exploited by ransomware gangs BleepingComputer

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.