Skip to content
Flash Briefing high HealthcareFinanceCritical InfrastructuremanufacturingTransport

Gunra Ransomware Actors Hit Healthcare, Finance, and Critical Infrastructure Across Five Continents

A coalition of six government agencies — CISA, the FBI, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s National Police Agency — published a joint advisory on 10 August 2026 warning of active attacks by Gunra ransomware actors. The advisory, designated AA26-222A, identifies Gunra as an expanding ransomware-as-a-service operation with confirmed victims across the Americas, Europe, the Middle East, Africa, and Asia-Pacific.

What Gunra Is

Gunra emerged in April 2025 as a ransomware variant built on the leaked Conti source code. Its operators spent the first several months refining the tooling before pivoting in early 2026 to a full RaaS model, recruiting affiliates through dark web forums and providing them with encryptors, playbooks, and a dedicated negotiation portal accessible via Tor.

The double-extortion approach is standard: data is exfiltrated before encryption, and victims who do not pay within the demanded window face publication of stolen material on Gunra’s dedicated leak site. The advisory notes that Gunra’s negotiation infrastructure is more polished than typical RaaS operations at this scale, with a customised victim-facing portal that includes countdown timers and a messaging function for ransom negotiation.

Initial Access Vectors

Gunra actors are gaining initial access primarily by exploiting two known vulnerabilities in internet-facing devices: CVE-2024-5559 and CVE-2025-24472. Both affect VPN and network edge appliances. Organisations with unpatched perimeter devices are the primary target population.

The advisory does not attribute Gunra to a specific nation-state. The RaaS structure means affiliates with varying levels of sophistication are conducting the intrusions, but the core operators are assessed to be operating outside of Five Eyes jurisdictions.

Sectors Targeted

The advisory identifies ten affected sectors: healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services. In practice, the breadth reflects the affiliate model — Gunra operators are not limiting targeting by sector, and affiliates appear to be opportunistic rather than vertically focused.

Healthcare and financial services organisations have received the most prominent mention in the advisory’s context section, consistent with observations from incident responders who note that these sectors face disproportionate pressure to pay due to operational dependencies on encrypted data.

Defensive Priorities

CISA’s guidance prioritises three immediate actions: patch CVE-2024-5559 and CVE-2025-24472 on any internet-facing devices, segment networks to limit lateral movement after an initial compromise, and verify that offline backups are current and cannot be reached by a compromised host.

Longer-term, the advisory recommends disabling unnecessary remote access services, enforcing multi-factor authentication on all remote access points, and reviewing VPN access logs for anomalous authentication patterns from unfamiliar source IPs — a common precursor to Gunra actor activity identified in post-incident investigations.

For organisations in the named sectors that have not yet applied the relevant patches, the advisory warrants urgent attention. The combination of a mature RaaS operation, active affiliate recruitment, and confirmed global victim count indicates Gunra is in an expansion phase rather than a steady state.