The National Security Agency said it has joined the FBI and partner agencies to issue a joint cybersecurity advisory on “#StopRansomware: Gunra Ransomware,” warning that the ransomware-as-a-service operation is targeting government, critical infrastructure, and other organizations worldwide.
According to the advisory released Aug. 10, Gunra first surfaced in 2025 before shifting to a RaaS model in 2026. Affiliates use a double-extortion playbook, encrypting victim systems while also stealing sensitive data and threatening to publish it on a dedicated leak site or sell it if payment isn’t made.
Investigators say the group emphasizes stealth and “defense impairment” to frustrate detection and analysis. While active inside networks, operators typically delete access logs and clear command histories to hide their tracks. Before triggering encryption, they exfiltrate sensitive information; the FBI has observed theft of business-critical documents, databases, personally identifiable information, and internal emails.
Victims have been identified across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific region. Impacted sectors span healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services.
The advisory urges network defenders to implement core mitigations and verify that existing controls work as intended. Priorities include patching known exploited vulnerabilities, maintaining and testing offline, immutable backups, and segmenting networks to limit lateral movement. The guidance also outlines incident response steps for suspected compromises.
The document is the latest entry in a broader #StopRansomware series that has included the 2023 #StopRansomware Guide and a 2023 advisory on ransomware attacks on critical infrastructure linked to DPRK malicious cyber activity.
The full advisory on Gunra is available via the Defense Department’s website. Additional resources and no-cost tools are available at stopransomware.gov, and the NSA maintains a library of cybersecurity advisories and technical guidance on its website.





