New Gunra Ransomware Threat Targets Businesses with Double-Extortion Tactics
CISA has released a joint advisory on Gunra, a ransomware variant first seen in 2025 that expanded into a full ransomware-as-a-service (RaaS) operation in 2026. Under this model, cybercriminal affiliates use the Gunra toolkit to target government agencies, critical infrastructure, and other organizations, sharing profits with the ransomware's developers.
Gunra affiliates use a 'double-extortion' approach: they encrypt a victim's data to disrupt operations, while also stealing copies of sensitive files. If the ransom isn't paid, attackers threaten to publish the stolen data on a dedicated leak site, adding reputational and legal pressure on top of operational disruption. This tactic makes backups alone insufficient protection, since data theft still occurs even if systems can be restored.
CISA recommends organizations prioritize patching known vulnerabilities in internet-facing systems such as VPN gateways and remote desktop services, which are common entry points for ransomware actors. Businesses should also maintain offline, immutable backups stored separately from their main network, and segment networks to limit how far attackers can move if they gain initial access.