Illustrative image generated with AI
Gunra: The RaaS Ransomware Targeting Exposed Networks and Critical Infrastructure
Gunra ransomware, derived from Conti, uses RaaS to target exposed networks and critical infrastructure with double extortion. Key defensive measures outlined.
Text generated by artificial intelligence, published without human review. AI transparency
An Operation Based on Conti’s Source Code
An advisory published on August 10, 2026, by the FBI, CISA, DC3, NSA, USSS, and the National Police Agency of the Republic of Korea describes the Gunra threat.
The ransomware emerged in April 2025 as a variant derived from the leaked Conti source code. Since early 2026, it has also been distributed through a ransomware-as-a-service (RaaS) model promoted on dark web forums and aimed at financially motivated criminal affiliates.
Gunra uses a double-extortion strategy: it first encrypts the targeted organization’s data, then threatens to publish it on its own dedicated leak site (DLS). Ransom negotiations take place through a customized portal accessible via Tor.
Initial Access and Operational Impact
Attacks may exploit systems exposed to the Internet, particularly:
- VPN gateways;
- infrastructure accessible through Remote Desktop Protocol (RDP);
- corporate networks containing data that can be exfiltrated.
Following the initial compromise, operators may attempt to move laterally across other systems on the network. The impact includes operational unavailability caused by encryption, data theft, and the potential public disclosure of sensitive information.
Additional consequences may include business disruption, interruptions to essential services, and financial pressure associated with ransom demands. The risk is considered high due to the combination of double extortion, the RaaS model, and the targeting of strategic organizations.
Sectors Most at Risk
Gunra may target government entities, critical infrastructure, and organizations across numerous sectors, including:
- healthcare and public health;
- finance and insurance;
- critical manufacturing and construction;
- transportation and logistics;
- utilities;
- higher education and research;
- media and communications;
- retail;
- professional services and nonprofit organizations.
No commercial vendors or specific software versions have been identified.
Defensive Measures and Available Indicators
Organizations should promptly apply patches for known and actively exploited vulnerabilities affecting Internet-facing systems, prioritizing VPN gateways and RDP infrastructure.
They should also:
- maintain offline, immutable backups that are physically separate from and segmented away from the primary network;
- regularly test backup restoration procedures;
- segment networks to limit lateral movement;
- integrate indicators of compromise into detection and response systems;
- closely monitor anomalous access to VPN, RDP, and systems containing sensitive data.
The indicators associated with advisory AA26-222A are available in 54 KB STIX XML and 61 KB STIX JSON formats. No CVE identifiers or individual indicators are included in the advisory text.
Sources
This article is an original reworking based on the sources below.
