type: incident ยท created: 2026-08-11 ยท updated: 2026-08-11 ยท tags: [incident, advisory, joint-advisory, cisa, fbi, ransomware, raas, conti, critical-infrastructure, sector-energy] ยท confidence: high ยท affected_sectors: [healthcare, financial-services, manufacturing, transport, government, utilities, critical-infrastructure] ยท au_impact: true
AA26-222A โ Joint Advisory on Gunra Ransomware Targeting Critical Infrastructure
AA26-222A is a joint #StopRansomware advisory published by the FBI, CISA, DoD DC3, NSA, US Secret Service and the Republic of Korea's National Police Agency detailing Gunra, a ransomware-as-a-service variant derived from the leaked Conti source code.
Summary
| Field | Detail |
|---|---|
| Advisory | AA26-222A |
| Actors | FBI, CISA, DoD DC3, NSA, US Secret Service, Republic of Korea National Police Agency |
| Threat | Gunra โ ransomware-as-a-service derived from leaked Conti source code |
| RaaS structure | Structured affiliate program launched early 2026 |
| Model | Double-extortion with Tor-based negotiation portal and dedicated leak site |
| Victim sectors | Healthcare, financial services, critical manufacturing, transport, government, utilities, academia, media, retail |
| Geography | Americas, Europe, the Middle East, Africa, Asia-Pacific |
| First emergence | April 2025 |
| Confidence | Confirmed (joint official advisory with IOCs) |
| Date | 2026-08-10 |
Key Details
- Gunra first emerged in April 2025 and launched a structured RaaS affiliate program in early 2026.
- Operates a double-extortion model with a Tor-based negotiation portal and dedicated leak site.
- Affiliates have been targeting government, critical manufacturing, healthcare, transport and utilities across multiple regions.
- The advisory includes patching priorities for internet-facing VPN/RDP, offline immutable backups, and network segmentation.
Significance
The advisory is a Five Eyes-aligned warning for critical infrastructure operators, naming healthcare, financial services, critical manufacturing, transport, government and utilities as primary targets. This aligns with ACSC's Essential Eight and ransomware guidance โ offline immutable backups and prioritised patching of internet-exposed VPN/RDP remain the highest-yield controls.
Related Pages
- Fbi Cisa And International Partners Warn Of Gunra Ransomware Targeting Critical โ Digest coverage of the advisory
Source
Sources: raw/digests/Cyber-Digest-2026-08-11