The Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI, the Department of Defense Cyber Crime Center, the National Security Agency, the U.S. Secret Service, and South Korea’s National Police Agency, has issued an official joint advisory warning organizations about a ransomware threat known as Gunra. The advisory, released on August 10, 2026, and designated AA26-222A, is part of CISA’s ongoing #StopRansomware campaign.
Federal Agencies Issue Joint Warning About Gunra
According to the official announcement, Gunra first emerged in April 2025 as a ransomware variant derived from leaked source code from an earlier ransomware family known as Conti. By early 2026, Gunra had expanded into a ransomware-as-a-service (RaaS) operation, meaning its developers began recruiting and supporting outside criminal affiliates through dark web forums to carry out attacks on their behalf.
The authoring agencies describe Gunra as using a “double-extortion” model. This means attackers not only encrypt victims’ data — making it inaccessible unless a ransom is paid — but also steal data beforehand and threaten to publish it on a dedicated public leak site if victims refuse to pay. Ransom demands are communicated through a customized negotiation portal accessible only through the Tor anonymity network.
The sectors identified in the advisory as targeted by Gunra include healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services. Victims have been observed across organizations in the Americas, Europe, the Middle East, Africa, and the Asia-Pacific region.
CISA’s advisory is primarily directed at organizational cybersecurity professionals, but the threat has broad implications. Healthcare systems, insurance providers, and government agencies — institutions that many Americans over 50 rely on for Medicare, Social Security, and other critical services — are specifically named as sectors at risk.
What Organizations Should Do if Gunra Activity Is Detected
The authoring agencies outlined several key protective actions for organizations. These include prioritizing the patching of known security vulnerabilities in internet-facing systems such as VPN gateways and remote desktop infrastructure, maintaining offline and immutable data backups stored in physically separate locations to allow recovery without paying a ransom, and segmenting computer networks to slow or prevent attackers from moving from one compromised system to others within an organization.
Technical indicators of compromise are available for download directly from CISA’s website for cybersecurity professionals to use in detecting potential Gunra activity. Additional resources and all #StopRansomware advisories can be found at stopransomware.gov.
Individuals and organizations are encouraged to verify their specific situation and cybersecurity needs directly with CISA or their relevant agency, as guidance may vary depending on sector and circumstances.
What to Read Next
More Americans Are Going Into Debt to Buy Groceries — Why Experts Say It’s a Warning Sign
17 Bills Worth More Than Face Value Hiding in Your Wallet Right Now – Spot Them Easily
Working While Collecting Social Security? 6 Earnings Rules Retirees Often Misunderstand
Read the full article here
