FORT MEADE, Md. — Today, the National Security Agency (NSA) joins the Federal Bureau of Investigation (FBI) and others in releasing a joint Cybersecurity Advisory, “
#StopRansomware: Gunra Ransomware,” as an ongoing effort to publish information about ransomware variants and threat actors. This includes sharing recently and historically observed tactics, techniques, procedures, and indicators of compromise to help organizations defend networks from ransomware.
Gunra is a ransomware-as-a-service (RaaS) program used by affiliates to target government, critical infrastructure, and other organizations worldwide, including in the U.S. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site and sell it if the ransom is not paid.
Gunra employs multiple stealth and defense impairment techniques to hinder detection and analysis. While active within victim networks, Gunra actors typically attempt to mask their presence by deleting system/network access logs and clearing command history. Also, prior to data encryption, Gunra actors collect sensitive victim data. The FBI observed actors collecting files from victims that included business-critical documents, databases, personally identifiable information, and internal email communications.
Victims span organizations in the Americas, Europe, Middle East, Africa, and Asia-Pacific across multiple sectors including healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services.
Cybersecurity architects, defensive cybersecurity analysts, vulnerability analysts, systems administrators, security systems managers, and other net defenders are advised to implement the recommended mitigations and validate their security controls: prioritizing patching known exploited vulnerabilities; implementing and testing offline, immutable backups; and segmenting networks. In the event of a potential compromise, the guidance also outlines recommended incident response procedures.
This report is part of a series. Reference two other previously released reports that NSA co-sealed:
• Joint Cybersecurity Information Sheet:
#StopRansomware Guide
• Joint Cybersecurity Advisory:
#StopRansomware: Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities
Additional Resources
• Visit
stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.
• Visit the
NSA’s full library for more cybersecurity information and technical guidance.
NSA Media Relations
MediaRelations@nsa.gov
443-634-0721
About the National Security Agency
Founded in 1952, NSA is a U.S. Department of War combat support agency and element of the U.S. Intelligence Community. The Agency’s mission is to provide foreign signals intelligence to policy makers and our military, and to prevent and eradicate cybersecurity threats to U.S. national security systems, with a focus on the Defense Industrial Base and the improvement of U.S. weapons’ security. From protecting U.S. warfighters around the world to enabling and supporting operations on land, in the air, at sea, in space, and in the cyber domain, NSA is committed to building public trust through transparency and protecting civil liberties and privacy consistent with our nation’s values.