EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Threat actor database
Threat actor profile

Gunra

Defensive profile aggregated solely from the catalogued evidence. Associations reflect the sources and are not independent EudorIA attribution.

Evidence status
verified
First observation
2025-04
Last observation
2026-08-11
Correlated signals
3
Observed picture

What the sources describe

CISA and partners issued a joint advisory detailing Gunra ransomware’s evolving tactics and double-extortion operations. AttackIQ emulations help organizations validate defenses against the adversary behaviors observed in Gunra attacks. The post Response to CISA Advisory (AA26-222A): #StopRansomware: Gunra Ransomware appeared first on AttackIQ . On August 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Defense Cyber Crime Center (DC3), National Security Agency (NSA), U.S. Secret Service (USSS), and Republic of Korea’s National Police Agency (KNPA) released a joint advisory to alert organizations to the emerging Gunra ransomware threat and to provide detection and mitigation guidance. This joint CSA is part of CISA’s ongoing #StopRansomware effort to provide defenders with intelligence and recommendations to help organizations identify, mitigate, and respond to ransomware activity. Gunra is a ransomware strain that emerged in April 2025. Developed in C/C++ and reportedly derived from leaked Conti ransomware source code, Gunra has since been observed targeting organizations across multiple industries. In early 2026, the group expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program advertised on underground forums. The program provides affiliates with access to a management panel, configurable ransomware builders, cross-platform payloads, and supporting documentation. Gunra operates a double-extortion model in which sensitive data is exfiltrated before systems are encrypted, with victims threatened with publication of their stolen information through a dedicated data leak site. Ransom negotiations are conducted through a Tor-based portal. According to the advis

Gunra Ransomware, un RaaS derivato da Conti1, è attivo con picco operativo tra l'agosto 2026. Colpisce multi-settorialmente aree come Sanità e Servizi Finanziari in tutto il mondo, utilizzando tecniche di initial access (T1190) e doppia estorsione.

Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra. Key Actions Prioritize patching known exploited vulnerabilities in internet-facing systems , including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure. Implement and test offline, immutable backups stored in a physically separate, segmented location to ensure recoverability without ransom payment. Segment networks to restrict lateral movement from an initially compromised device to other systems in the organization. Indicators of Compromise For a downloadable copy of indicators of compromise, see: AA26-222A STIX XML (54 KB) AA26-222A STIX JSON (61 KB) Intended Audience Organizations: Government, Critical Infrastructure Sectors: Healthcare and public health , financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities , utilities, academia, media and communications, retail, and professional and nonprofit services. Roles: Cybersecurity architects , defensive cybersecurity analysts , vulnerability analysts , systems administrators , and security systems managers . Introduction Note: T

AliasesGunra Ransomware
Ransomwarevariante ransomware Gunra (derivata dal codice sorgente trapelato di Conti), Gunra Ransomware encryptor
MalwareGunra Ransomware encryptor (derivante dal leak del codice Conti1)
Named targetsAgenzie governative, Organizzazioni delle infrastrutture critiche, Sanità, Servizi Finanziari, Manifattura Critica, Costruzioni, Logistica, Servizi Governativi, Utilities · US, Stati Uniti, Corea del Sud, Americhe, Europa, Medio Oriente, Africa, Asia-Pacifico (APAC)
Modus operandi

Observed methods and techniques

4 structured pieces of evidence
Initial AccessT1190

Sfruttamento di vulnerabilità note su sistemi esposti a Internet

Accesso tramite sfruttamento di vulnerabilità conosciute nei sistemi esterni.

2 linked sources
Lateral MovementT1021

Utilizzo di tecniche per muoversi da un dispositivo inizialmente compromesso ad altri sistemi della rete aziendale

Movimento laterale all'interno dell'infrastruttura di rete.

2 linked sources
ImpactT1486

Cifratura dei dati sensibili sui sistemi locali

Blocco e cifratura di dati localmente conservati.

2 linked sources
ImpactT1659

Minaccia di pubblicazione su portali Tor dedicati (modello a doppia estorsione)

Rischio di divulgazione dei dati rubati.

2 linked sources
Risk reduction

How to prepare the defence

Controls linked to the evidence
01

Patching immediato delle vulnerabilità note ed esposte

02

Segmentazione di rete rigorosa per impedire i movimenti laterali

03

Implementazione di backup immutabili e testati offline

EudorIA

Security Assessment

Verifica esposizione, configurazioni e priorita di remediation prima che una tecnica osservata diventi un incidente.

Approfondisci il servizio →
EudorIA

Managed WAF

Protegge applicazioni e API esposte con regole gestite, virtual patching e analisi degli eventi applicativi.

Approfondisci il servizio →
EudorIA

Identity Security Managed

Riduce abuso di credenziali e accessi anomali con MFA, controllo delle identita e verifica continua.

Approfondisci il servizio →
EudorIA

Privileged Access Management

Separa e governa gli account privilegiati, limitando escalation e persistenza amministrativa.

Approfondisci il servizio →
EudorIA

XDR per utente/mese

Correla endpoint, identita ed esecuzioni sospette per contenere malware e attivita post-compromissione.

Approfondisci il servizio →
EudorIA

Managed Next-Generation Firewall

Applica segmentazione, controllo applicativo e contenimento dei canali di comando e controllo.

Approfondisci il servizio →

The measures listed reduce likelihood and impact but do not guarantee the absolute prevention of an attack.

Tor intelligence

Catalogued onion sources

0

No onion source associated with this group.

Evidence trail

Linked observations

Last 3
DateSignalTypeConfidence
11/08/2026Response to CISA Advisory (AA26-222A): #StopRansomware: Gunra Ransomwareadvisoryeditorial_osint
11/08/2026Threat actor: Gunraransomwarecurated_osint
10/08/2026#StopRansomware: Gunra Ransomwareransomwareofficial