Home/Threat Intelligence/CBN-2026-025
HighAdvisoryTLP: CLEARCBN-2026-025 · 11 Aug 2026
Gunra ransomware destroyed backups at the primary site and the DR site in the same intrusion
A six-agency advisory documents Gunra actors deleting backup and archive data on backup infrastructure at both the production data centre and the disaster recovery centre. The same administrative credentials reached both, so geographic separation bought nothing.
At a glance
Affected
Organisations with Fortinet FortiOS or FortiProxy exposed to the internet, and any estate where the DR backup infrastructure trusts primary-site administrative credentials.
Impact
Encryption of production plus destruction of the recovery tier at both sites — the scenario your DR plan is written to prevent, executed in a single intrusion.
Action
Separate DR backup credentials from production and primary-site backup identities, enforce retention locks the backup administrator cannot shorten, keep one copy genuinely offline, and patch CVE-2024-55591 and CVE-2025-24472.
Client status
Immutability and credential separation are verified quarterly on all Acronis-protected estates we manage. Clients on self-managed backup should ask us for the DR credential-separation review.
Detail
Most ransomware advisories tell you the actors deleted shadow copies. This one is worth reading properly because it goes further. In at least one documented case, Gunra operators destroyed backup and archived data held on backup infrastructure at the primary data centre and at the disaster recovery centre. Not shadow copies on production hosts — the backup estate itself, at both sites.
Why the second site did not help
Because the same administrative credentials reached both. Geographic separation protects against fire, flood and power. It does not protect against an attacker who has domain administrator and a route to the DR network, which is precisely what a flat backup identity model provides. If the account that manages your primary repository can also authenticate to the DR repository, you do not have two copies. You have one copy in two buildings.
This is the failure mode that separates real immutability from a second copy somewhere else, and it is the single most common gap we find in backup design reviews. The fix is unglamorous: a separate identity store for the DR tier, no shared domain trust, retention locks enforced at the repository or object-lock layer that the backup administrator account itself cannot shorten, and multi-person authorisation for retention changes and repository deletion.
The way in was a known, patchable flaw
Initial access came through authentication bypasses in Fortinet FortiOS and FortiProxy — CVE-2024-55591 and CVE-2025-24472 — plus credential exposure and SSH access-control weaknesses on VPN gateways, and default credentials where account lockout was not enforced. Nothing novel. From there: Mimikatz and Impacket's secretsdump.py for credentials, then psexec.py and smbclient.py over SMB for lateral movement.
Gunra has been observed since April 2025, launched a formal ransomware-as-a-service programme in January 2026, and has victims across the Americas, Europe, the Middle East, Africa and Asia-Pacific in ten named sectors including healthcare, financial services, manufacturing, transport, government and utilities.
One detection to add this week
Route backup job deletions and repository purges to your security monitoring as alerts, not just to the backup operator's mailbox. In almost every case we review, the backup platform logged the destruction correctly and nobody was watching that log with an incident-response mindset.
If you find evidence of this activity, do not begin remediation before preserving evidence — console and appliance audit logs are frequently short-retention and will roll off. Acronis MDR provides around-the-clock detection and response for covered estates; otherwise reach us through the contact page and we will advise on preservation before containment.
Sources
Cybernalyst's analysis and recommendations are our own. The underlying research is credited below — please read the original reporting.
- #StopRansomware: Gunra Ransomware (AA26-222A)FBI, CISA, DC3, NSA, US Secret Service and Republic of Korea National Police Agency·10 August 2026