Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-11 ยท updated: 2026-08-11 ยท tags: [incident, ransomware, raas, joint-advisory, cisa, fbi, conti, critical-infrastructure, sector-energy] ยท confidence: high ยท affected_sectors: [healthcare, financial-services, manufacturing, transport, government, utilities, critical-infrastructure] ยท au_impact: true

FBI, CISA and International Partners Warn of Gunra Ransomware Targeting Critical Infrastructure

The FBI, CISA, DoD DC3, NSA, US Secret Service and the Republic of Korea's National Police Agency released a joint #StopRansomware advisory (AA26-222A) detailing Gunra, a ransomware-as-a-service variant derived from the leaked Conti source code.

Summary

Field Detail
Threat Gunra ransomware-as-a-service (Conti-derived)
First emerged April 2025
RaaS affiliate program Launched early 2026
Model Double-extortion with Tor-based negotiation portal and dedicated leak site
Victim sectors Healthcare, financial services, critical manufacturing, transport, government, utilities, academia, media, retail
Geography Americas, Europe, Middle East, Africa, Asia-Pacific
Confidence Confirmed (joint official advisory with IOCs)
Date 2026-08-10

Key Details

  • Gunra first emerged April 2025 and launched a structured RaaS affiliate program in early 2026.
  • Operates a double-extortion model with a Tor-based negotiation portal and dedicated leak site.
  • Affiliates have been targeting government, critical manufacturing, healthcare, transport and utilities across multiple regions.
  • The advisory includes patching priorities for internet-facing VPN/RDP, offline immutable backups, and network segmentation.

Significance

The advisory is a Five Eyes-aligned warning for critical infrastructure operators, aligning with ACSC's Essential Eight and ransomware guidance โ€” offline immutable backups and prioritised patching of internet-exposed VPN/RDP remain the highest-yield controls for the affected sectors.

Related Pages

  • Aa26 222A โ€” The advisory page (AA26-222A)

Source

Sources: raw/digests/Cyber-Digest-2026-08-11