Gunra launches RaaS affiliate program and recruits initial access brokers
Threat Actor Meta
Summary
Hide ▲
Show ▼
Gunra expanded its criminal operating model in January 2026 by launching a ransomware-as-a-service (RaaS) platform, increasing affiliate reach and lowering the barrier to intrusion. The group began recruiting initial access brokers and adopted the Golden Community branding alias to support the expansion. The shift strengthens its ability to scale extortion operations across enterprise networks and widen access to victims.
Related Happenings
Gunra ransomware CVE exploitation and double-extortion activity
Malware Activity
H score26
First: 10.08.2026 15:00
Last: 10.08.2026 15:00
Sources 1
How related:
Attacks deploying the ransomware have leveraged security flaws in internet-facing Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS and FortiProxy (CVE-2025-24472) appliances to obtain initial access, and then deploy the Gunra ransomware as part of a double extortion model that combines data exfiltration and data encryption for maximum impact.
About this happening:
Gunra ransomware is being used by affiliates against critical infrastructure sectors worldwide, with a joint advisory from CISA, FBI, DC3, NSA, USSS, and KNPA saying t...
Gunra ransomware CVE exploitation and double-extortion activity
Malware ActivityHow related: Attacks deploying the ransomware have leveraged security flaws in internet-facing Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS and FortiProxy (CVE-2025-24472) appliances to obtain initial access, and then deploy the Gunra ransomware as part of a double extortion model that combines data exfiltration and data encryption for maximum impact.
About this happening: Gunra ransomware is being used by affiliates against critical infrastructure sectors worldwide, with a joint advisory from CISA, FBI, DC3, NSA, USSS, and KNPA saying t...
UNC6671 diversifies extortion operations across multiple public brands
Threat Actor Meta
H score44
First: 06.08.2026 23:07
Last: 06.08.2026 23:07
Sources 1
About this happening:
UNC6671 has shifted to a multi-brand extortion model, widening its operating footprint across Redact, Pink, Helix, and Falcon and increasing the difficulty of tracking...
UNC6671 diversifies extortion operations across multiple public brands
Threat Actor MetaAbout this happening: UNC6671 has shifted to a multi-brand extortion model, widening its operating footprint across Redact, Pink, Helix, and Falcon and increasing the difficulty of tracking...
DevMan-Funky Mantis ecosystem shift changes threat-actor operations
Threat Actor Meta
H score46
First: 25.07.2026 12:53
Last: 25.07.2026 12:53
Sources 1
About this happening:
DevMan has consolidated its RaaS affiliate portal, tightening control over payload creation, victim handling, and payouts across its criminal service network. PRODAFT...
DevMan-Funky Mantis ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: DevMan has consolidated its RaaS affiliate portal, tightening control over payload creation, victim handling, and payouts across its criminal service network. PRODAFT...
Scattered Spider reclassified as a decentralized collective of independent clusters
Threat Actor Meta
H score26
First: 07.07.2026 17:00
Last: 07.07.2026 17:00
Sources 1
About this happening:
Scattered Spider has been reclassified as a decentralized cybercrime collective, changing how its persistence and resilience are understood. The shift suggests independe...
Scattered Spider reclassified as a decentralized collective of independent clusters
Threat Actor MetaAbout this happening: Scattered Spider has been reclassified as a decentralized cybercrime collective, changing how its persistence and resilience are understood. The shift suggests independe...
DragonForce / Hackledorb pivots from RaaS to a formalized cartel structure
Threat Actor Meta
H score26
First: 18.06.2026 16:30
Last: 18.06.2026 16:30
Sources 1
About this happening:
Hackledorb has pivoted DragonForce from a conventional ransomware-as-a-service (RaaS) model into a formalized cartel structure, signaling a more organized and dura...
DragonForce / Hackledorb pivots from RaaS to a formalized cartel structure
Threat Actor MetaAbout this happening: Hackledorb has pivoted DragonForce from a conventional ransomware-as-a-service (RaaS) model into a formalized cartel structure, signaling a more organized and dura...
Timeline
-
11.08.2026 12:47 3 articles · 2h ago
Gunra launches RaaS affiliate program and recruits initial access brokers
Initial DisclosureIn January 2026, Gunra shifted to a scalable affiliate model by standing up a RaaS platform. It also started recruiting initial access brokers to broaden access to enterprise targets and support extortion operations.
Show sources
- US and South Korea warn of Gunra ransomware targeting govt agencies — www.bleepingcomputer.com — 11.08.2026 12:47
- US and South Korea warn of Gunra ransomware targeting govt agencies — www.bleepingcomputer.com — 11.08.2026 12:47
- Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks — thehackernews.com — 11.08.2026 12:16