CISA Advisory: #StopRansomware: Gunra Ransomware
ID: c756ccb3-e9cd-5fe1-9027-e66626ba0eee
STIX ID: report--c756ccb3-e9cd-5fe1-9027-e66626ba0eee
Feed Name: DataBreaches.Net
Gunra is a ransomware-as-a-service (RaaS) active since 2025 and expanded in 2026; affiliates use it to target government, critical infrastructure, and other organizations with a double-extortion model that both encrypts data and threatens public release on a dedicated leak site. The advisory provides technical details, detection and mitigation guidance — prioritizing patching of internet-facing systems (VPN/RDP), implementing offline immutable backups, and network segmentation — and points to CISA for downloadable indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
