#StopRansomware: Gunra Ransomware (opens in a new tab)
Why readCISA's joint advisory on Gunra ransomware-as-a-service, with TTPs and detection and mitigation guidance for a group now hitting government and critical infrastructure.
Gunra emerged as a ransomware variant in 2025 and moved to a RaaS model in 2026, running double extortion with a dedicated leak site for exfiltrated data. The advisory sets out affiliate tradecraft plus tailored detection and mitigation, and the key actions point at known exploited vulnerabilities in internet-facing VPN gateways and RDP-exposed infrastructure as the initial access to close, alongside offline immutable backups and segmentation to limit lateral movement. Treat this as the current authoritative reference for Gunra hunting and for justifying backup and segmentation work upward.
Indicators4
- Hashes
2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d191f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9
Also covered byDataBreaches.net (opens in a new tab),The Record (opens in a new tab).