An advisory issued jointly this week by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency alerted organizations about an emerging threat from the Gunra ransomware group and provided guidance on detection and mitigation.
Gunra emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti ransomware source code. It expanded in 2026 as a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums for cybercriminals. Gunra actors demand ransom through a customized Tor-based negotiation portal and threaten to publish exfiltrated data on a leak site if victims do not comply. According to the alert, Gunra is actively recruiting penetration testers and ethical hackers as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access. I’m hoping ethical hackers will remain “ethical.”
Organizations listed on the actors’ leak site have included multiple business sectors across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific region including:
• Healthcare and public health;
• Financial services and insurance;
• Critical manufacturing and construction;
• Transportation systems and logistics;
• Government services and facilities;
• Utilities;
• Academia;
• Media and communications;
• Retail; and
• Professional and nonprofit services.
Organizations in these sectors are urged to implement the recommendations for mitigation including:
• Prioritizing the patching of known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure;
• Implementing and regularly testing offline, immutable backups stored in a physically separate, segmented location to ensure recovery without paying a ransom; and
• Segmenting networks to restrict lateral movement from an initially compromised device to other systems within the organization.
The advisory provides technical details that should be reviewed and implemented by IT professionals, including pinpointing the legitimate tools that are being used by Gunra that can evade existing monitoring tools.
Gunra Ransomware Group Hitting Multiple Sectors
Thursday, August 13, 2026
An advisory issued jointly this week by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency alerted organizations about an emerging threat from the Gunra ransomware group and provided guidance on detection and mitigation.
Gunra emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti ransomware source code. It expanded in 2026 as a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums for cybercriminals. Gunra actors demand ransom through a customized Tor-based negotiation portal and threaten to publish exfiltrated data on a leak site if victims do not comply. According to the alert, Gunra is actively recruiting penetration testers and ethical hackers as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access. I’m hoping ethical hackers will remain “ethical.”
Organizations listed on the actors’ leak site have included multiple business sectors across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific region including:
• Healthcare and public health;
• Financial services and insurance;
• Critical manufacturing and construction;
• Transportation systems and logistics;
• Government services and facilities;
• Utilities;
• Academia;
• Media and communications;
• Retail; and
• Professional and nonprofit services.
Organizations in these sectors are urged to implement the recommendations for mitigation including:
• Prioritizing the patching of known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure;
• Implementing and regularly testing offline, immutable backups stored in a physically separate, segmented location to ensure recovery without paying a ransom; and
• Segmenting networks to restrict lateral movement from an initially compromised device to other systems within the organization.
The advisory provides technical details that should be reviewed and implemented by IT professionals, including pinpointing the legitimate tools that are being used by Gunra that can evade existing monitoring tools.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | The ‘year of AI’: 2026 sees influx of ransomware attacks | -2 | 6 | 26-06-2026 |
| 2 | Ransomware in 2026: More groups, more victims, no slowdown | 0 | 12.14 | 24-07-2026 |
| 3 | DragonForce Ransomware Is Hiding in Microsoft Teams Traffic | 0 | 7 | 17-06-2026 |
| 4 | Researchers Uncover First Fully Agentic AI Ransomware Attack | 0 | 8 | 06-07-2026 |
| 5 | NCC Group Warns Ransomware, State Hackers, and AI Fraud Tools Are Colliding | 0 | 7 | 24-06-2026 |
| 6 | Crypto Exploits Siphon Record $1,100,000,000 From Digital Asset Protocols in Six Months: Report | 0 | 33.73 | 03-08-2026 |
| 7 | CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang | 0 | 8 | 09-06-2026 |
| 8 | How ransomware syndicates weaponize corporate-style organization | 0 | 7 | 30-06-2026 |
| 9 | AI Agent Carries Out Ransomware Attack in Possible Cybercrime First | 0 | 8 | 07-07-2026 |