The Department of Defense Cyber Crime Center (DC3), in coordination with the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), U.S. Secret Service (USSS), and Korean National Police Agency (KNPA), has released a joint cybersecurity advisory addressing Gunra ransomware activity.
The advisory provides technical details, indicators of compromise (IOCs), and mitigation guidance to help government, critical infrastructure, and other organizations identify and protect against Gunra ransomware.
The Threat
Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations.
The Gunra ransomware variant first appeared in 2025 and expanded into RaaS operations in 2026. The actors use a double-extortion model, encrypting data while also threatening to publish exfiltrated information on a dedicated leak site if a ransom is not paid.
The advisory provides technical details about this activity, along with tailored detection and mitigation guidance to help organizations strengthen their defenses against Gunra.
Take Action Now
Organizations and network defenders should:
-
Prioritize patching known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure.
-
Implement and test offline, immutable backups stored in a physically separate, segmented location to support recovery without paying a ransom.
-
Segment networks to restrict lateral movement from an initially compromised device to other systems within the organization.
-
Review the advisory's indicators of compromise for evidence of potential Gunra ransomware activity.
The advisory is intended for government and critical infrastructure organizations, including healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services.
Read the Full Advisory (PDF)
|