Last Updated On

Six Agencies Flag Gunra as StormEncryptor DeadLock Exploit Edge Flaws
Six agencies dropped a joint advisory on Gunra the same day Microsoft detailed StormEncryptor and DeadLock while CISA escalated SharePoint and edge appliance flaws into active ransomware vectors. Conti derived double extortion met Rust based resilience and RMM god mode access across Fortinet N central LoadMaster SonicWall and on premises SharePoint. The window left no room for delayed patching or untested backups.
Defenders now face confirmed initial access through public facing authentication bypasses and deserialization RCEs that feed rapid encryption and cloud exfiltration. Offline immutable recovery remains the only reliable counter once notes appear and volumes turn to ENCRT encrypted or dlock.
Hunt the notes first then rotate every exposed management plane before the next 72 hours close.
10
CVSS Score
55
IOC Count
17
Source Count
82
Confidence Score
CVE-2024-55591, CVE-2025-24472, CVE-2026-18577, CVE-2026-18556, CVE-2026-8037, CVE-2026-15409, CVE-2026-15410, CVE-2026-45659, CVE-2026-20337, CVE-2026-20338, CVE-2026-12537, CVE-2026-54316, CVE-2026-64638, CVE-2026-33691, CVE-2023-37679, CVE-2023-43208, CVE-2024-1709, CVE-2024-1708, CVE-2024-27198, CVE-2024-27199, CVE-2023-48788, CVE-2025-10035
Gunra, Golden Community, Storm 1175, DeadLock operators, Lynx, INC, UTA0533, UNC6671, Head Mare, Shai Hulud operators
Healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities, utilities, academia, media and communications, retail, professional and nonprofit services, IT, mining, hospitality, consumer goods, MSP MSSP environments
Americas, Europe, Middle East, Africa, Asia Pacific, North America, South America, Australia, China, Indonesia, Japan, Poland, United States
Chapter 01 - Executive Overview
Board brief multi agency Gunra warning lands on a live edge exploitation day
On 10 August 2026 the FBI CISA DC3 NSA U.S. Secret Service and Korea National Police Agency published joint advisory AA26 222A on Gunra a Conti1 derived double extortion RaaS active since April 2025 and expanded via affiliate recruitment in 2026 Victims span government and critical infrastructure sectors globally Documented initial access includes Fortinet FortiOS FortiProxy authentication bypasses CVE 2024 55591 and CVE 2025 24472 plus VPN credential SSH weaknesses Impact combines ChaCha20 plus RSA 4096 encryption ENCRT cloud exfiltration OneDrive SharePoint Mega and backup destruction
The same 24 hour window confirms a perimeter and RMM exploitation wave that feeds ransomware economics
• Microsoft documents Storm 1175 China linked financially motivated former Medusa user deploying new StormEncryptor likely after N able N central CVE 2026 18577 CISA KEV auth bypass patch bypass of CVE 2026 18556 • Microsoft publishes deep analysis of DeadLock a Rust encryptor with Polygon plus Session decentralized recovery chat used by Lynx INC affiliates more than 80 DLS victims by July 2026 • CISA KEV already lists Progress LoadMaster CVE 2026 8037 unauth command injection CVSS approximately 9.6 with FCEB due date 10 August 2026 • Reporting on 10 August states CISA flagged SonicWall SMA1000 CVE 2026 15409 15410 as exploited by ransomware gangs prior zero day since June UTA0533 tooling • CISA updated KEV on 11 August to flag CVE 2026 45659 SharePoint deserialization RCE CVSS 8.8 as exploited in ransomware attacks escalating from July 1 generic KEV listing over 8500 internet exposed servers 200 plus still unpatched
Executive actions next 24 to 72h • Force patch and forensically triage internet facing Fortinet N central LoadMaster SonicWall SMA1000 and on premises SharePoint • Assume RMM compromise equals customer estate risk revoke Take Control sessions rotate MSP credentials • Verify offline immutable backups and restore tests Gunra explicitly destroys backup tiers • Hunt ransom note filenames and encrypted extensions before negotiating any extortion contact • Enable AMSI integration for SharePoint and ensure Defender detections active
Uncertainty Storm 1175 to CVE 2026 18577 link is Microsoft likely not proven INC attribution on SMA1000 ransomware is Resecurity via press not CISA named SharePoint ransomware operators remain unnamed
Chapter 02 - Threat & Exposure Analysis
Gunra RaaS operational picture AA26 222A
Gunra runs a classic double extortion model exfiltrate encrypt negotiate on Tor qTox leak or sell data on DLS if unpaid RaaS packaging includes builder cross platform lockers Windows plus Linux and affiliate docs FBI notes recruitment of access brokers Encryption is multi threaded ChaCha20 plus RSA 4096 notes R3ADM3.txt extensions ENCRT and historically CRYPT Linux GNRA
Access and identity abuse • Exploit public facing VPN firewall flaws • Default SSL VPN admin creds without lockout • Steal modify accounts to skip password change • Hijack VDI sessions • MFA bypass via attacker chosen OTP on auth portal server side backdoor not user facing social engineering standard MFA fatigue detections will not catch it • NTDS dump via Impacket secretsdump.py • Pass the hash ticket
Movement and collection • Impacket psexec.py smbclient.py over SMB • RDP across VDI AD IT desktops • Archive with 7 Zip WinRAR • Exfil via main.exe targeting M365 OneDrive SharePoint Mega FileZilla RClone • Volumes up to tens of TB observed
Ops security • Night hour ops 22 00 to 06 00 • Clear logs and shell history • Debugger checks IsDebuggerPresent • Delete VSS via WMI • Wipe backup DC DR copies
Storm 1175 operational shift to StormEncryptor
Microsoft assesses Storm 1175 as China based financially motivated historically fast N day zero day user Mirth ScreenConnect TeamCity FortiClient EMS GoAnywhere and others deploying Medusa New activity StormEncryptor C plus plus extension encrypted note !!!README FIRST!!!.txt 3 day negotiate window Post compromise AnyDesk SimpleHelp Advanced IP Scanner Mimikatz LSASS Speed initial access to exfil ransomware often within days Access vector likely N central CVE 2026 18577 admin god mode on vulnerable RMM
DeadLock technical threat Microsoft 2026 08 10
DeadLock differentiates on resilience not novel crypto alone • Config XOR decoded CIS ME language geofence self delete • Pre crypto UAC spam via random cmd token privileges recycle bin wipe service process kill list Defender VSS Hyper V AD EDR ish processes full event log clear plus channel disable • Crypto XChaCha20 content plus Curve25519 NaCl crypto box key wrap partial encryption tiers by file size extension dlock • Post branded wallpaper HOW RECOVER.UID.txt RECOVERY CHAT.UID.html SPA using Polygon contracts for proxy URL blog and Session messenger for E2E chat Wasabi S3 browser for leaks • Operators published more than 80 orgs on DLS by July 2026 Europe heavy affiliates include Lynx INC ecosystems
Edge KEV wave enabling ransomware economics • Progress LoadMaster CVE 2026 8037 Unauth RCE on ADC edge KEV 792 attempts 65 IPs 41d FCEB due 10 Aug • N able N central CVE 2026 18577 18556 MSP pivot to all managed tenants • SonicWall SMA1000 CVE 2026 15409 15410 Enterprise VPN remote access ransomware association on KEV approximately 380 internet exposed • Fortinet FortiOS Proxy CVE 2024 55591 2025 24472 Explicit Gunra access path • Microsoft SharePoint CVE 2026 45659 Deserialization RCE now flagged for ransomware use over 8500 exposed 200 plus unpatched
Secondary window noise do not over weight Check Point 10 Aug bulletin NC Ports operational cyberattack Ryde 4.5M customer PII Coinkite Coldcard theft approximately 1367 BTC 88.6M claimed Beacon CRM charity breach Gemini CLI Claude Code critical issues Shai Hulud npm CHAINDROP UNC6671 vishing vs US finance macOS ClickFix stealers Cisco ClamAV DoS with public PoC ITW not claimed
Chapter 03 - Operational Response
Immediate response playbook prioritized
P0 Assume breach triage on internet facing access planes 0 to 24h • Inventory FortiGate FortiProxy SSL VPN N central self hosted LoadMaster ADC WUI API SonicWall SMA1000 on premises SharePoint Enterprise Server 2016 2019 Subscription Edition • Patch to vendor fixed builds or remove from internet place admin planes on jump hosts only • For each exposed device class pull auth logs config diffs unexpected admins scheduled tasks and outbound tunnels before reboot if possible • N central specific apply greater than or equal 2026.3.1 Hotfix path per N able current advisory hunt Cloudflared service anomalous svchost.exe under user Documents Take Control session anomalies listed bad IPs from vendor advisory • LoadMaster upgrade GA greater than or equal 7.2.63.2 or LTSF greater than or equal 7.2.54.18 restrict API WUI to management network review web logs for pre auth command endpoint abuse • SMA1000 confirm mid July hotfix tier hunt Volexity malware families if appliance was unpatched in June July • Fortinet hunt forticloud sync superuser and other unexpected local admins validate CVE 2024 55591 2025 24472 patch level • SharePoint patch to fixed builds SharePoint 2016 greater than or equal 16.0.5552.1002 SharePoint 2019 greater than or equal 16.0.10417.20128 Subscription Edition greater than or equal 16.0.19725.20280 enable Windows AMSI integration for SharePoint web applications ensure Microsoft Defender Antivirus detections active monitor for post exploitation even on patched systems if exposed prior
P1 Ransomware readiness parallel • Snapshot offline immutable backup integrity Gunra deletes primary and DR backups • Block egress to known DLS onion categories where policy allows alert on Mega RClone FileZilla mass transfers from servers • Disable macro PSExec lateral paths enforce tiered admin phishing resistant MFA on VPN VDI RDP • If Linux encryption with GNRA suspected Gunra preserve timestamps AA26 222A cites weak srand time NULL PRNG enabling possible key reconstruction March 2026 research cited by agencies
P2 Identity and cloud • Revoke refresh tokens review Entra M365 unified audit log for mass OneDrive SharePoint download Gunra main.exe pattern • Reset privileged passwords hashes if NTDS or LSASS dump suspected Gunra Impacket Storm Mimikatz • MSP credential rotation across tenant break glass accounts customer notification decision tree
P3 Comms and reporting • US FBI IC3 field office CISA Incident Reporting 1 844 SAY CISA contact cisa.dhs.gov USSS field office as applicable • South Korea KNPA 112 cybercrime portal • Do not recommend ransom payment agency position
Containment order if encryption ongoing Isolate preserve volatile evidence kill encryptor processes disable rogue RMM reset creds from known good medium restore from tested offline backup harden threat hunt residual tunnels SSH Cloudflare AnyDesk
• 2022 Conti source leak Gunra lineage basis • 2025 04 Gunra first observed FBI • 2025 06 to 07 Gunra clearnet DLS mirror datapub news active • 2025 mid Gunra Linux variant reporting • 2025 07 DeadLock first observed Microsoft • 2025 07 to 2026 07 DeadLock builds victim count more than 80 on DLS • 2026 01 Gunra formal RaaS Golden Community branding • 2026 03 Gunra Tor DLS migration Linux PRNG weakness research • 2026 04 Last prior Storm 1175 activity before new wave Microsoft • 2026 05 Microsoft releases patches for CVE 2026 45659 • 2026 06 04 CVE 2026 8037 NVD published • 2026 06 22 approximately UTA0533 SMA1000 zero day exploitation begins Volexity • 2026 mid 07 SonicWall patches CVE 2026 15409 15410 warns active exploit • 2026 07 01 CISA adds CVE 2026 45659 to KEV catalog for general active exploitation 3 day FCEB remediation deadline set • 2026 07 02 Canadian Centre for Cyber Security issues AL26 015 alert • 2026 07 14 SMA1000 CVEs added CISA KEV 3 day FCEB clock at that time • 2026 07 31 approximately N central CVE 2026 18577 exploited vendor CISA context • 2026 08 02 N able hotfix 2026.3.1.7 StormEncryptor timeframe association • 2026 08 03 CVE 2026 18577 to CISA KEV • 2026 08 05 CVE 2026 18556 to CISA KEV reporting • 2026 08 07 CVE 2026 8037 to CISA KEV ClamAV 1.5.4 patch • 2026 08 04 Last LoadMaster exploit attempts in KEVIntel set 5 attempts • 2026 08 10 AA26 222A Gunra joint advisory Microsoft DeadLock blog Microsoft StormEncryptor disclosures consulted sources SonicWall ransomware KEV story LoadMaster FCEB due date Check Point weekly TI • 2026 08 11 consulted sources Cisco ClamAV high bugs plus public PoC US ROK Gunra warning amplification CISA updates KEV catalog to flag ransomware specific exploitation of CVE 2026 45659
Chapter 04 - Detection Intelligence
Gunra encryptor and tooling agency verified • Windows encryptor FindFirstFileW FindNextFileW across drives A to Z excludes system dirs and exe dll sys multi thread ChaCha20 plus RSA 4096 rename to ENCRT note R3ADM3.txt • VSS kill example AA26 222A cmd.exe c C Windows System32 wbem WMIC.exe shadowcopy where ID equals guid delete • Impacket psexec.py smbclient.py secretsdump.py • Exfil binary main.exe two SHA 256s in agency table for OneDrive SharePoint • Other binaries cryptor.exe msmp.exe hashes in Ch4 IOC • Fortinet persistence account forticloud sync with superuser plus hard coded password via scheduled task abuse on vulnerable FortiOS CVE 2024 55591 24472 context • Linux note GNRA ELF variant weak PRNG preserve mtimes for possible recovery
StormEncryptor Microsoft • Language C plus plus • Extension encrypted • Note !!!README FIRST!!!.txt every scanned directory • Negotiate window 3 days • LOLbins tradecraft AnyDesk SimpleHelp Advanced IP Scanner Mimikatz • Access likely N central auth bypass CVE 2026 18577 patch bypass of CVE 2026 18556
DeadLock encryptor Microsoft deep dive • Config Embedded blob XOR 8 byte key fields include victim UID operator pubkey encryption rules geofence LANGIDs process service stop lists notes HTML • Geofence exit LANGIDs include 1049 RU 1058 UK 1059 BE FA AR variants CAUC CAS languages and others immediate self delete • Elevation Random 8 char uppercase cmd plus ShellExecuteW RunAs retry less than or equal 10 • Privileges SeDebugPrivilege SeRestorePrivilege SeBackupPrivilege SeTakeOwnershipPrivilege SeAuditPrivilege SeSecurityPrivilege • Icon brand C ProgramData UID.ico plus HKLM SOFTWARE Classes dlock DefaultIcon • Defense kill Services windefend vss swprv wbengine mssearch vmcompute vmms adws ntds kdc and others Processes msmpeng securityhealthservice smartscreen onedrive dropbox anydesk putty explorer powershell taskmgr cmd and others • Log wipe Clear Application Security Setup System PowerShell and others set all WINEVT Channels Enabled equals 0 plus restrictive SDDL wevtapi enumerate clear • Throttle Pause new file dispatch if mem greater than 29 percent or CPU idle less than 30 percent • Crypto Per file XChaCha20 key nonce ephemeral Curve25519 NaCl crypto box with zero nonce safe due to unique ephemeral keys footer with pubkey plus dDlK magic plus optional FA flag • Partial crypt Rules string 1000 05052429880 025124288000 010524288000 F991114288000 leads to 100 percent 50 percent 25 percent 10 percent chunked full by size tiers 512 byte stride pattern • Notes HOW RECOVER.UID.txt second pass RECOVERY CHAT.UID.html on drive roots plus Desktops • Decentralized C2 chat Polygon contracts chat proxy 0x8EF7c3e531d871D3B9D559722DE77EB1dEc19dAe selector 0x933a9ce8 blog 0x757984507c82c8dA1d3969c535dB5706eEE6426C 0xd4070542 Session swarm via proxy Wasabi file browser • Pubkey sample 03bf50bbf97c4e951e66ff12b689a37a3ce675b4921e254eae76da77573843e4a9 SEC1 prefixed 32 byte Curve25519 material after prefix • Self delete Batch loops delete encryptor then itself
LoadMaster CVE 2026 8037 technical • CWE 77 command injection in API command endpoints • Root cause analysis improper handling uninitialized heap leading to pre auth RCE • Unauthenticated attacker arbitrary commands on appliance often as privileged service context • Affects LoadMaster lineage hardware VLM cloud also referenced family products in secondary reporting ECS Connection Manager MOVEit WAF verify on Progress advisory before asset mark up
SharePoint CVE 2026 45659 technical • CWE 502 deserialization of untrusted data issue in SharePoint server side object processing • Exploitable over the network AV N with low complexity AC L requiring low privileges PR L and no user interaction UI N yielding high confidentiality integrity availability impact • Insufficient source data on the specific deserialization gadget chain payload delivery mechanism or post RCE tooling used in the ransomware campaigns CISA references this level of detail has not been published in a technical advisory as of report time
DeadLock Microsoft high confidence
Gunra AA26 222A agency vet historical IPs
StormEncryptor Storm 1175
LoadMaster exploitation attempts eSentire via consulted sources attempts not confirmed C2
SharePoint insufficient source data no IOCs published for the ransomware specific exploitation confirmed Aug 11
Bulk Ingest AA26 222A STIX JSON XML from CISA as system of record
SIGMA Gunra generic Conti class VSS deletion via WMIC
SIGMA Impacket style secretsdump lateral tooling host artifacts
SIGMA DeadLock pre encryption tradecraft bundle
SIGMA Ransom note file create multi family
YARA DeadLock footer extension heuristics
YARA Gunra note extension
SIEM field logic practical detections
Microsoft Defender XDR vendor stated DeadLock signals • Alert titles to wire to IR DeadLock ransomware was detected prevented Ransomware behavior detected in the file system File backups were deleted Suspicious wallpaper change Possible data exfiltration
Splunk SPL mass file extension mutation
Elastic KQL N central Cloudflared persistence
Network proxy DeadLock recovery chat RPCs Alert HTTPS to polygon bor rpc.publicnode.com polygon.drpc.org polygon pokt.nodies.app polygon rpc.com 1rpc.io matic polygon.meowrpc.com from hosts that also created RECOVERY CHAT.*.html or many .dlock files Alone RPC traffic is common correlate
Fortinet malicious account config user local CLI history username equals forticloud sync OR new super admin not in approved baseline
LoadMaster pre auth API abuse WAF ADC logs unauthenticated requests to command API endpoints with shell metacharacters in parameters including apiuser accessv2 class paths per secondary technical writeups Correlate source IPs to eSentire set as weak prior
M365 Gunra style cloud collection
Tune baselines main.exe UA may not appear prefer anomalous volume plus unusual client app
SharePoint anomalous process spawn from web application pool
SharePoint unpatched version exposure hunting
Consolidated matrix primary Gunra source mapped • Initial Access T1190 T1133 T1078.001 002 • Execution T1106 T1047 T1059.003 • Persistence T1098 T1133 • Privilege Escalation T1078.* • Defense Evasion Stealth T1622 T1070.003 T1678 T1679 T1685 • Credential Access T1003 003 T1040 T1539 T1555 T1556.006 • Discovery T1083 T1049 • Lateral Movement T1021.001 T1021.002 T1550.002 T1550.003 • Collection T1560 T1530 T1005 T1114 • C2 T1105 T1572 • Exfiltration T1567 T1048 • Impact T1486 T1490 T1657
DeadLock Storm 1175 see Field 21 inferred tables do not merge into Gunra heat maps without separate layer
SharePoint T1190 only source confirmed All downstream tactics techniques insufficient source data
D3FEND control checklist • Patch edge D3 PM on KEV list weekly automation • Segment East west deny SMB RDP workstation default • Identity Phishing resistant MFA kill default VPN admins • Backup Offline immutable plus restore drill quarterly • Detect encryptors EDR ransomware canaries plus note filename rules • MSP risk Out of band verification of RMM admin actions
Chapter 05 - Governance, Risk & Compliance
Regulatory directive hooks • CISA KEV plus BOD 26 04 FCEB required action on CVE 2026 8037 by 2026 08 10 N central CVEs earlier August dues document exception risk if missed SharePoint original 3 day window from July 1 listing has already lapsed any FCEB entity still unpatched is out of compliance • AA26 222A CPGs Maps to CISA NIST Cross Sector CPGs patch 2.B backups 3.I 3.O 1.C accounts 2.A 2.E least privilege 3.G segmentation 3.I MFA 3.F restrict CLI 3.G 3.M • Sector regulators Healthcare HIPAA breach risk if Gunra exfil finance transportation government DLS publication equals regulatory notification clocks • MSP supply chain N central and SMA1000 MSSP deployments create multi tenant notification obligations prepare customer comms templates • International KNPA partnership signals ROK victimology multinationals with APAC footprints should share IOC packages with regional CSIRTs • Organizations subject to NIS2 EU SEC cyber disclosure rules or sector specific regulation HIPAA for healthcare victims GLBA for financial services victims should treat confirmed Gunra compromise as a reportable incident under applicable breach notification thresholds given the double extortion data exfiltration component • CISA Eviction Strategies Tool Playbook NG plus COUN7ER is explicitly recommended for structured eviction planning against the mapped TTPs • Private sector organizations should treat KEV listing plus confirmed ransomware use as sufficient justification for emergency change patching outside normal change windows
Governance metrics for leadership • Percent internet facing KEV assets patched or isolated 100 percent less than or equal 72h of KEV add • Backup restore test success critical systems greater than or equal monthly • Privileged VPN accounts with phishing resistant MFA 100 percent • EDR coverage on servers plus VDI 100 percent • Time to detect ransom note filename less than 5 minutes automated
Legal Preserve evidence before mass reimage coordinate with counsel on extortion communications agencies discourage payment
Chapter 06 - Adversary Emulation
Purple team scenarios authorized lab only
Scenario A Gunra lite ATT&CK aligned • External exploit or simulate Fortinet auth bypass create local admin • Deploy Impacket like SMB exec to DC staging host • secretsdump against lab DC PtH to VDI broker • Stage 7 Zip archive of sensitive share upload to lab S3 Mega stand in • WMIC delete lab shadow copy drop R3ADM3.txt encrypt canary files with test ChaCha harness non destructive preferred Success criteria for blue detect T1190 appliance anomaly Impacket 7045 NTDS access VSS delete note drop
Scenario B Storm 1175 velocity • Simulate N central admin API auth bypass mock • Install AnyDesk SimpleHelp in lab • Run Advanced IP Scanner Mimikatz against lab LSASS credential guard off lab only • Deploy benign encryptor that only renames canaries to encrypted plus note !!!README FIRST!!!.txt within 48h kill chain timer Success criteria RMM new install alert LSASS access block note detection less than 5m
Scenario C DeadLock resilience behaviors • Drop test binary that writes random XXXXXXXX.cmd registers fake dlock DefaultIcon clears a lab only event log channel changes wallpaper policy key • Optional HTML file calling public Polygon RPC read only eth call monitor egress Success criteria ASR EDR blocks registry canary correlated RPC host alert
Scenario D SharePoint focus • Validate patch compliance scanning and web application firewall coverage for known SharePoint deserialization exploit patterns rather than attempting to replicate an undocumented ransomware payload chain • Simulate anomalous child process from w3wp.exe SharePoint context to test detection of post RCE activity
Safety No production encryption no real ransom infrastructure interaction isolate lab from corporate identity providers
• AA26 222A six agency joint CSA with MITRE v19.1 plus STIX +35 • Microsoft TI primary technical blogs statements DeadLock Storm 1175 +20 • CISA KEV confirmations LoadMaster N central SMA1000 SharePoint +15 • Independent consulted sources corroboration without contradiction +10 • NVD record alignment on CVE 2026 8037 KEV metadata +5 • Storm 1175 access vector hedged likely 5 • INC SMA1000 single commercial attribution 3 • Some CVSS vectors not NVD finalized 3 • DeadLock Storm MITRE partly inferred 2 • SharePoint lacks actor IOCs post exploitation detail moderate weight • Total 82
