Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-11 ยท updated: 2026-08-11 ยท tags: [incident, advisory, joint-advisory, cisa, fbi, ransomware, raas, conti, critical-infrastructure, sector-energy] ยท confidence: high ยท affected_sectors: [healthcare, financial-services, manufacturing, transport, government, utilities, critical-infrastructure] ยท au_impact: true

AA26-222A โ€” Joint Advisory on Gunra Ransomware Targeting Critical Infrastructure

AA26-222A is a joint #StopRansomware advisory published by the FBI, CISA, DoD DC3, NSA, US Secret Service and the Republic of Korea's National Police Agency detailing Gunra, a ransomware-as-a-service variant derived from the leaked Conti source code.

Summary

Field Detail
Advisory AA26-222A
Actors FBI, CISA, DoD DC3, NSA, US Secret Service, Republic of Korea National Police Agency
Threat Gunra โ€” ransomware-as-a-service derived from leaked Conti source code
RaaS structure Structured affiliate program launched early 2026
Model Double-extortion with Tor-based negotiation portal and dedicated leak site
Victim sectors Healthcare, financial services, critical manufacturing, transport, government, utilities, academia, media, retail
Geography Americas, Europe, the Middle East, Africa, Asia-Pacific
First emergence April 2025
Confidence Confirmed (joint official advisory with IOCs)
Date 2026-08-10

Key Details

  • Gunra first emerged in April 2025 and launched a structured RaaS affiliate program in early 2026.
  • Operates a double-extortion model with a Tor-based negotiation portal and dedicated leak site.
  • Affiliates have been targeting government, critical manufacturing, healthcare, transport and utilities across multiple regions.
  • The advisory includes patching priorities for internet-facing VPN/RDP, offline immutable backups, and network segmentation.

Significance

The advisory is a Five Eyes-aligned warning for critical infrastructure operators, naming healthcare, financial services, critical manufacturing, transport, government and utilities as primary targets. This aligns with ACSC's Essential Eight and ransomware guidance โ€” offline immutable backups and prioritised patching of internet-exposed VPN/RDP remain the highest-yield controls.

Related Pages

Source

Sources: raw/digests/Cyber-Digest-2026-08-11