On August 10, 2026, a coalition of U.S. and South Korean government agencies, including CISA, the FBI, and the NSA, released a joint cybersecurity advisory (CSA) AA26-222A, titled "#StopRansomware: Gunra Ransomware." The advisory details the activities of a Ransomware-as-a-Service (RaaS) operation that is actively targeting a broad range of critical infrastructure sectors globally. Gunra, which is based on the leaked source code of the infamous Conti ransomware, employs a double-extortion model, exfiltrating sensitive data before encryption and threatening to publish it on a dedicated leak site if the ransom is not paid.
The Gunra operation has been observed targeting government, healthcare, financial services, transportation, and utility sectors across the Americas, Europe, Africa, and the Asia-Pacific region. The group functions as a RaaS platform, recruiting affiliates through dark web forums and offering them an 80% share of ransom payments. This model allows the group to scale its operations rapidly by leveraging a network of initial access brokers and financially motivated cybercriminals.
The attack lifecycle follows a typical double-extortion pattern:
.ENCRT extension is appended.Gunra ransomware is a 32-bit Windows PE file derived from the leaked Conti v3 source code. Its use of a multi-threaded architecture allows for rapid encryption of files on the compromised system. The encryption scheme, combining the ChaCha20 stream cipher for file content and RSA-4096 for key protection, is robust and makes recovery without the attacker's private key computationally infeasible.
Key TTPs identified in the advisory include:
.ENCRT extension.The global targeting of critical infrastructure by the Gunra RaaS operation poses a significant risk to public safety and national security. A successful attack on a healthcare facility, utility, or government agency can lead to severe operational disruptions, financial loss, and the exposure of vast amounts of sensitive citizen data. The double-extortion tactic increases pressure on victims to pay, as the consequences of a data leak can sometimes be more damaging than the encryption itself, involving regulatory fines, reputational damage, and loss of public trust.
No specific file hashes, IP addresses, or domains were provided in the source articles.
Security teams may want to hunt for the following patterns to detect Gunra activity:
.ENCRTreadme.txtqtox.sovssadmin.exe delete shadowsvssadmin to delete volume shadow copies, a common precursor to encryption.vssadmin), and the creation of ransom notes in multiple directories..ENCRT or files named readme.txt.The joint advisory provides several key mitigation recommendations:
Prioritize patching of internet-facing systems and known exploited vulnerabilities.
Mapped D3FEND Techniques:
Enforce MFA for all remote access services to mitigate credential-based attacks.
Mapped D3FEND Techniques:
Segment networks to limit lateral movement and contain the impact of a breach.
Mapped D3FEND Techniques:
Gunra ransomware variant first appears.
Gunra evolves into a Ransomware-as-a-Service (RaaS) model.
CISA, FBI, NSA, and South Korean agencies issue a joint advisory on Gunra.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.