Gunra is a ransomware-as-a-service operation that uses double extortion to target government, critical infrastructure, and other organizations, combining data theft with file encryption. The advisory highlights Gunra’s use of exploitable VPN and firewall devices, stolen credentials, and lateral movement tools to spread across networks and includes mitigation guidance to reduce exposure. #Gunra #Conti #CISA #FBI #KNPA
Keypoints
- Gunra emerged in 2025 and expanded into a formal RaaS program in 2026.
- The group uses double extortion by encrypting data and threatening to leak stolen files.
- Initial access often comes from exploited vulnerabilities in VPN gateways and firewall appliances.
- Gunra relies on credential theft, session hijacking, and lateral movement with Impacket and RDP.
- Defenders should patch internet-facing systems, isolate backups, and segment networks to limit spread.
Read More: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a