CISA Issues Advisory on Gunra Ransomware RaaS Threat
Authorities warn of double-extortion ransomware derived from leaked Conti code targeting government and critical infrastructure globally
Key Takeaways
- Gunra ransomware expanded to RaaS operations in 2026, leveraging leaked Conti source code.
- Double-extortion model involves data encryption and threats to publish exfiltrated data on a dedicated leak site.
- Initial access is achieved through exploitation of known vulnerabilities in internet-facing VPN gateways and RDP infrastructure.
- Authoring agencies include FBI, CISA, DC3, NSA, USSS, and KNPA.
- Affected sectors span government, critical infrastructure, healthcare, finance, manufacturing, transportation, utilities, academia, media, retail, and nonprofit services.
Quick answers
- What happened?
- The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and international partners have released joint advisory AA26-222A warning of Gunra ransomware, a ransomware-as-a-service (RaaS) variant that expanded operations in 2026. Gunra employs a double-extortion model, encrypting victim data and threatening publication on a dedicated leak site. Initial access is achieved through exploitation of known vulnerabilities in internet-facing VPN gateways and Remote Desktop Protocol (RDP) infrastructure. The advisory provides detection guidance, indicators of compromise, and mitigation recommendations for affected sectors.
- What should defenders do?
- Prioritize patching known exploited vulnerabilities in internet-facing systems including VPN gateways and RDP infrastructure; implement and test offline immutable backups stored in physically separate segmented locations; segment networks to restrict lateral movement from initially compromised devices.
The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Department of Defense Cyber Crime Center (DC3), National Security Agency (NSA), U.S. Secret Service (USSS), and Republic of Korea's National Police Agency (KNPA) have released joint cybersecurity advisory AA26-222A regarding the Gunra ransomware threat. Gunra emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from leaked Conti ransomware source code. In early 2026, the operators expanded operations through a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums, allowing financially motivated cybercriminals to deploy the malware.
Gunra affiliates target government, critical infrastructure, and other organizations primarily through initial access via known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure. The ransomware employs a double-extortion model: data is encrypted, and victims are threatened with publication of exfiltrated data on a dedicated leak site (DLS) if the ransom is not paid.
Victims observed on the actors' dedicated leak site span multiple sectors across the Americas, Europe, Middle East, Africa, and the Asia-Pacific, including healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services.
The advisory recommends that organizations prioritize patching known exploited vulnerabilities in internet-facing systems, implement and test offline immutable backups stored in physically separate segmented locations, and segment networks to restrict lateral movement from initially compromised devices.
Security Details
Gunra ransomware variant derived from leaked Conti source code; expanded to RaaS in 2026; initial access via known exploited vulnerabilities in VPN gateways and RDP-exposed infrastructure; double-extortion model encrypting data and threatening publication on dedicated leak site.
Mitigation
Prioritize patching known exploited vulnerabilities in internet-facing systems including VPN gateways and RDP infrastructure; implement and test offline immutable backups stored in physically separate segmented locations; segment networks to restrict lateral movement from initially compromised devices.
Sources
CISA Advisories
#StopRansomware: Gunra Ransomware
Aug 10, 2026 · 12:00
Original link
Related Security News

Bitget Reports $388M Loss Following Exploitation of Third-Party Security Product Flaw
Bitget disclosed that an attacker stole approximately $388 million by exploiting a vulnerability in a third-party security product integrated into the exchange's infrastructure. The threat actor used the flaw to obtain high-level internal credentials, which were subsequently used on September 24 to issue fraudulent withdrawal commands to Bitget's wallet system. The exchange confirmed that most user funds remain secure, though the full extent of exposure is under investigation.




