What should managed IT leaders do after the Gunra ransomware advisory?
A Gunra ransomware checklist should verify patched internet-facing VPN and firewall systems, restricted RDP and VDI access, separate privileged accounts, MFA coverage, reviewed domain-controller activity, monitored OneDrive and SharePoint exfiltration paths, segmented networks, immutable backups, restore tests, and a rehearsed incident-response process with evidence leadership can inspect.
The news hook is concrete. On August 10, 2026, CISA, the FBI, the Department of Defense Cyber Crime Center, NSA, the U.S. Secret Service, and the Republic of Korea’s National Police Agency released a joint advisory on Gunra ransomware, an emerging ransomware-as-a-service threat affecting government, critical infrastructure, healthcare, financial services, utilities, academia, professional services, and other sectors.1 CISA revised the related press release on August 11.2
For Datapath clients, the advisory reads like a managed IT operating test. Gunra actors have exploited internet-facing firewall and VPN appliances, abused default credentials, modified accounts, dumped credentials, moved through RDP and SMB, collected cloud data from Microsoft OneDrive and SharePoint, and attempted to delete backup data before encryption.1 That touches the same environments we support through managed cybersecurity services, managed firewall services, Microsoft 365 identity security services, and incident response retainer services.
| Gunra risk area | What the advisory describes | Evidence executives should request |
|---|---|---|
| Internet-facing edge systems | Exploitation of firewall, VPN, and SSL-VPN appliances | Asset list, firmware status, KEV review, emergency patch tickets |
| Privileged access | Default credentials, unused accounts, account modification, credential dumping | Admin account inventory, MFA coverage, lockout policy, removal log |
| Lateral movement | RDP, SMB administrative shares, pass-the-hash, pass-the-ticket | Segmentation diagram, privileged pathway review, domain-controller logs |
| Cloud data theft | OneDrive and SharePoint exfiltration using malicious tooling | Microsoft 365 audit logs, DLP alerts, unusual archive/upload review |
| Recovery inhibition | Shadow-copy deletion and backup/archive deletion | Immutable backup status, restore tests, backup-admin separation |
Need to turn the Gunra advisory into a managed IT action plan?
Datapath helps regulated teams verify exposed assets, privileged access, Microsoft 365 logging, segmentation, backup evidence, and response ownership.
Why does Gunra change the ransomware readiness conversation?
Gunra changes the conversation because it links ordinary IT hygiene failures to a modern double-extortion playbook. The advisory is not only about malware encryption. It is about edge-device exposure, administrator pathways, cloud collaboration data, backup survivability, and whether the organization can detect suspicious activity before the ransom note appears.
What did the advisory say about who is exposed?
CISA’s advisory says Gunra is used by affiliates to target government, critical infrastructure, and other organizations. The intended sectors include healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services.1
That sector list matters because many regional organizations assume ransomware advisories are written for massive enterprises. That is the wrong read. A city department, school district, clinic group, credit union, construction company, nonprofit, or 150-person professional-services firm can run the same exposed VPN, the same Microsoft 365 tenant, the same backup architecture, and the same lean IT staffing model that the advisory describes.
Why are VPN and firewall appliances the first checkpoint?
The FBI observed Gunra actors obtaining initial access primarily through known vulnerabilities in internet-facing devices, including firewall and VPN appliances. The advisory specifically names FortiOS and FortiProxy authentication-bypass vulnerabilities CVE-2024-55591 and CVE-2025-24472, and KNPA observed exploitation of credential exposure and SSH access-control issues in internet-facing VPN gateways.1
That is why a vague patch report is not enough. Leaders need a current inventory of every internet-facing remote-access path: VPN, firewall administrative console, remote desktop gateway, VDI portal, RMM tool, file-transfer service, and vendor support tunnel. If an asset is exposed, it needs an owner, version, patch state, authentication requirement, logging source, and emergency disablement path.
What makes the privileged-access pattern dangerous?
Gunra actors were observed using default credentials where account lockout controls were absent, identifying unused accounts that could reach both internet-facing and internal networks, modifying account configuration, dumping NTDS password hashes from domain controllers with Impacket, and using pass-the-hash or pass-the-ticket techniques for lateral movement.1
In our experience working with regulated and mid-market teams, this is where ransomware preparation often fails. The organization may enforce MFA for normal users but leave appliance administrators, service accounts, shared vendor credentials, break-glass accounts, or old VDI accounts under-reviewed. Datapath treats those accounts as control-plane risk. If a single stale account can reach identity, backups, or remote access, the environment is not resilient.
What should a Gunra ransomware checklist include?
A useful Gunra ransomware checklist should translate the advisory into verifiable work. The goal is not to memorize every indicator of compromise. The goal is to prove that the organization can close common entry points, detect credential abuse, contain lateral movement, protect recoverability, and document who owns each decision.
1. Prove the exposed-asset inventory
Start with the public attack surface. Document every firewall, VPN, SSL-VPN, VDI portal, RDP exposure, RMM tool, file-transfer system, web application, and cloud admin endpoint. For each asset, capture:
- product and version
- business owner and technical owner
- internet exposure and admin-access method
- latest security advisory review date
- KEV Catalog match status
- MFA and lockout coverage
- logging destination
- emergency shutdown procedure
CISA’s separate Known Exploited Vulnerabilities alerts repeatedly tell organizations to prioritize risk-based remediation for actively exploited vulnerabilities, and its August 17, 2026 alert again encouraged all organizations to adopt risk-based vulnerability management even when federal mandates apply directly only to federal agencies.3 Pair that with our guide on building a vulnerability management program for mid-market companies if the current process is still scanner-first rather than owner-first.
2. Lock down privileged and remote access
The Gunra advisory gives leaders a practical question: can any unused, default, stale, or vendor-controlled account reach both the edge and the internal network? If the answer is unknown, the organization has an access-governance problem.
Review these areas first:
- Separate named administrator accounts from normal user accounts.
- Remove or disable unused local, domain, appliance, and VPN accounts.
- Confirm account lockout policies on externally reachable authentication paths.
- Require MFA for VPN, webmail, VDI, RMM, cloud administration, and critical systems.
- Review service accounts and shared vendor credentials for scope and rotation.
- Hunt for new accounts, role changes, and authentication-process changes.
For Microsoft-centered environments, use our Entra ID access review checklist for privileged accounts and Microsoft 365 guest user access review checklist alongside Datapath’s Microsoft 365 identity security services.
3. Watch OneDrive and SharePoint as exfiltration paths
Gunra is especially relevant to Microsoft 365-heavy organizations because the advisory says the FBI observed a malicious main.exe used to exfiltrate victim data from Microsoft OneDrive and SharePoint. The same section says actors generated compressed archives with sensitive data and exfiltrated archives to Mega, with exfiltrated volume ranging up to tens of terabytes for at least one victim.1
That pushes Microsoft 365 monitoring beyond routine login alerts. Teams should review unusual downloads, archive creation, mass file access, unusual external uploads, suspicious OAuth/app activity, guest or vendor access, and changes in SharePoint sharing posture. Our SharePoint external sharing audit checklist and OAuth app consent audit checklist cover the collaboration and application-consent side of that exposure.
4. Protect backups from the same credentials used in production
CISA’s key Gunra actions include implementing and testing offline, immutable backups stored in a physically separate, segmented location.1 The advisory also says Gunra actors deleted volume shadow copies and, in one case, deleted backup and archived data stored at both the primary data center and disaster recovery center before and after ransomware deployment.1
That is the blunt lesson: backup existence is not backup survivability. Leaders should ask for evidence that backup administration is separated, repositories are segmented, immutable or offline copies exist, alerts are monitored, restore tests are recent, and the recovery order is documented. Datapath’s disaster recovery services and backup and disaster recovery guide are the right next step when backup dashboards look green but restore proof is thin.
5. Segment networks around identity, data, and recovery
The advisory calls for network segmentation to restrict lateral movement from an initially compromised device to other systems in the organization.1 That sounds simple until the team maps real traffic. Ransomware containment has to account for identity systems, backup consoles, file shares, databases, VDI, EHR or SIS platforms, finance systems, network management, and vendor support pathways.
A practical segmentation review should answer:
- Can a normal workstation reach domain controllers directly?
- Can VDI users reach administrative interfaces?
- Can vendor support paths reach backup infrastructure?
- Can a compromised file server talk freely to database servers?
- Are backup repositories reachable from the same admin accounts used in production?
- Are firewall changes reviewed against ransomware-containment assumptions?
This is where managed firewall services stop being a device-management line item and become an operational resilience control.
How should leaders turn the advisory into a 30-day action plan?
Leadership should turn the advisory into a focused evidence sprint. The first 30 days should not attempt to rebuild the entire security program. It should prove whether the most exploited pathways are known, owned, monitored, and recoverable.
Days 1-7: inventory and triage the edge
Ask IT or the MSP for a current list of externally reachable systems and remote-access paths. Rank them by exploitability, privilege, business criticality, and recovery impact. Close obvious exposures, assign owners to ambiguous assets, and document exceptions with dates rather than vague risk acceptance.
Use CISA’s #StopRansomware Guide as a broader reference because it separates prevention best practices from response actions and is written for IT professionals and incident coordinators.4
Days 8-15: review credentials, admins, and lateral movement
Audit privileged accounts, local administrators, appliance administrators, VPN groups, VDI access, RDP usage, SMB administrative shares, service accounts, and vendor pathways. Confirm MFA and lockout controls. Review whether logs from edge systems, domain controllers, Microsoft 365, EDR, and firewalls are actually monitored or merely retained.
If the organization needs outside operating discipline, Datapath’s co-managed IT services can help internal teams keep business context while we add process, evidence, escalation, and technical execution.
Days 16-23: validate cloud-data and backup evidence
Review Microsoft 365 audit logs, SharePoint and OneDrive external sharing, suspicious archive creation, large downloads, third-party app consent, and cloud DLP coverage. Then run a restore test for one critical workload and one file-level recovery scenario. Keep the evidence: ticket, screenshot, recovery time, owner, gaps, and next test date.
For healthcare, finance, K-12, and municipal teams, this evidence matters beyond ransomware. It supports insurer conversations, board reporting, HIPAA, GLBA, CJIS, FERPA-adjacent governance, vendor oversight, and customer due diligence.
Days 24-30: rehearse the first hour
Run a short tabletop exercise around a suspected Gunra-style intrusion before encryption. Decide who can isolate systems, disable VPN, revoke admin sessions, preserve logs, contact legal or insurance, coordinate vendors, and communicate with executives. CISA’s advisory says if compromise is detected before encryption, organizations should isolate compromised hosts, initiate threat hunting, report as appropriate, apply eviction countermeasures, and harden the network.1
The output should be a decision log, not a slide deck. If the team cannot make decisions in the exercise, it will not make them cleanly during an incident.
Why Datapath for a Gunra ransomware checklist
Datapath helps regulated and mid-market organizations turn ransomware advisories into operating controls: asset ownership, patch cadence, identity review, firewall governance, Microsoft 365 visibility, backup evidence, segmentation, and incident-response decision rights. A Gunra ransomware checklist only matters if it produces proof that controls are working before a real incident.
Our team supports healthcare, K-12, financial services, municipal, professional-services, and mid-market environments where downtime, data exposure, and audit evidence are business risks. If you are evaluating managed IT partners, start with our MSP evaluation guide and ask whether the provider can show evidence for each checklist item rather than only naming tools.
Frequently Asked Questions
What is Gunra ransomware?
Gunra is a ransomware-as-a-service threat first observed by the FBI in April 2025. CISA’s August 2026 advisory says Gunra uses double extortion: actors exfiltrate sensitive data before encryption and threaten to publish or sell the data if victims do not pay.1
Which organizations should care about Gunra?
Government, healthcare, financial services, utilities, academia, professional services, nonprofits, construction, transportation, manufacturing, and other critical-infrastructure-adjacent organizations should care. The advisory’s intended audience is broad because the relevant entry points are common: VPNs, firewalls, remote access, privileged accounts, cloud data, and backups.1
What is the first Gunra ransomware checklist item?
The first item is a current inventory of internet-facing remote-access and edge systems, including VPNs, firewalls, VDI, RDP, RMM, and file-transfer services. Each asset should have an owner, patch state, MFA requirement, logging source, emergency disablement path, and known-vulnerability review.
Why does Gunra matter for Microsoft 365 teams?
Gunra matters for Microsoft 365 teams because the advisory says actors used malware to exfiltrate data from OneDrive and SharePoint. That makes cloud audit logging, sharing review, app-consent governance, unusual download monitoring, and data-loss prevention part of ransomware readiness rather than separate compliance projects.1
Are immutable backups enough to stop Gunra impact?
No. Immutable or offline backups are essential, but they are not enough by themselves. Organizations also need separated backup administration, segmentation, monitored backup deletion attempts, restore testing, documented recovery order, and response authority so backup data survives the same credential compromise that affects production.
Sources
Footnotes
-
CISA: #StopRansomware: Gunra Ransomware, AA26-222A ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13
-
CISA: CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors ↩
-
CISA: CISA Adds One Known Exploited Vulnerability to Catalog, August 17, 2026 ↩