GUNRA is a ransomware-as-a-service (RaaS) targeting government and critical infrastructure, first emerging in 2025 and expanding operations in 2026. It employs a double-extortion strategy, encrypting data and threatening to publish stolen data if the ransom is not paid. The advisory offers technical specifics and guidance for organizations to protect against Gunra.
Key actions include prioritizing patches for known vulnerabilities, implementing offline immutable backups, and segmenting networks to limit lateral movements. Additionally, indicators of compromise are provided with downloadable resources.