The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI), in collaboration with US government and international partners, released a Joint Cybersecurity Advisory alerting organizations about the emerging Gunra ransomware threat and to provide detection and mitigation guidance.
Gunra first emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti ransomware source code. As of early 2026, Gunra expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums to financially motivated cybercriminals. Gunra actors demand ransom via a customized, Tor-based negotiation portal and threaten to publish exfiltrated data on a dedicated leak site (DLS) if victims do not comply.
Organizations are encouraged to implement the recommendations in the mitigations section of this advisory to mitigate cyber threats related to Gunra ransomware.

