
CISA and partners publish Gunra ransomware defense guidance for critical infrastructure
CISA and partner agencies published new Gunra ransomware guidance with IOCs, attack patterns and mitigations for defenders.
CISA, the FBI, the Defense Department Cyber Crime Center, the NSA, the U.S. Secret Service and South Korea's National Police Agency have published a joint #StopRansomware advisory on Gunra, a ransomware-as-a-service operation aimed at government, critical infrastructure and other organizations. The advisory, released August 10, 2026, gives defenders a consolidated view of the group's tactics, tools, infrastructure indicators and mitigations.
The agencies say Gunra first appeared as a ransomware variant in 2025 and expanded into an affiliate-driven service model in 2026. That shift matters because it can let different intrusion teams reuse the same locker, infrastructure and extortion playbook across many targets. The advisory describes a double-extortion model in which attackers encrypt systems while also threatening to publish stolen data on a dedicated leak site or sell it if a victim refuses to pay.
What defenders should note
The technical details emphasize common enterprise weak points rather than exotic malware alone. Investigators observed Gunra actors exploiting public-facing FortiGate firewall and SSL-VPN appliances, abusing default credentials, and taking advantage of weak access controls to gain administrator access. South Korean police also observed credential-exposure and SSH access-control vulnerabilities in internet-facing VPN gateways being used for unauthorized remote access.
- Gunra affiliates have used legitimate remote access tools including AnyDesk and Google Remote Desktop to maintain access.
- The advisory lists use of post-exploitation utilities such as Mimikatz and Impacket for credential theft and lateral movement.
- Observed activity included deleting volume shadow copies, clearing logs and command history, and timing activity for late night or early morning to reduce detection.
- Data theft paths included Mega for web-service exfiltration and FileZilla for FTP transfer.
The agencies also describe attacks against backup infrastructure, including one case where actors deleted backup and archived data at both primary and disaster-recovery environments before and after ransomware deployment. That detail reinforces why ransomware planning now has to include backup isolation, recovery testing and monitoring for unusual archive creation or remote-transfer activity before encryption starts.
CISA's mitigation advice centers on controls that reduce the blast radius of a compromise: phishing-resistant multifactor authentication, fast remediation of known exploited vulnerabilities, network segmentation, least-privilege administrative access, and auditing of privileged accounts. For security teams, the value of the advisory is practical rather than speculative. It gives incident responders fresh indicators to hunt, maps activity to MITRE ATT&CK techniques, and clarifies which defensive controls are most relevant when Gunra affiliates target exposed VPNs, remote access paths and backup systems.
Sources
Cover photo by Adventure Studio on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment