CISA, FBI, and Partners Release Joint Cybersecurity Advisory on Gunra Ransomware

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI), in collaboration with U.S. government and international partners, released a joint Cybersecurity Advisory, #Stopransomware: Gunra Ransomware, part of an ongoing series detailing ransomware variants and threat actors. This joint advisory provides technical details on Gunra activity, along with detection and mitigation guidance to help protect at-risk organizations across government and critical infrastructure.

Gunra first emerged in April 2025 and expanded to a formal ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums. Gunra actors use a double-extortion model, meaning actors both encrypt and exfiltrate sensitive data to create two forms of leverage for collecting ransom payments. They demand ransom via a Tor network-based negotiation portal and threaten to publish stolen data on their dedicated leak site (DLS) if victim organizations do not pay within five to seven days. As part of the 2026 expansion, Gunra actors have adopted branding aliases (including Golden Community) and further commercialized by actively recruiting penetration testers and ethical hackers as initial access brokers in exchange for a share of ransom profits. They have also demonstrated the ability to disable backup features, and in one instance, prevented restoration by deleting backup and archived data stored at both a primary data center and disaster recovery center. Victim organizations listed on Gunra’s DLS site are from multiple sectors across the world.

CISA, the FBI, and authoring agencies urge organizations to implement the advisory’s mitigations, including the following key actions:

  • Prioritize patching known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure.
  • Implement and test offline, immutable backups stored in a physically separate, segmented location to ensure recoverability without ransom payment.
  • Segment networks to restrict lateral movement from an initially compromised device to other systems in the organization.

Read the full advisory for more information on how to protect your organization from Gunra.