#StopRansomware: Gunra Ransomware
This advisory details the Gunra ransomware, a sophisticated threat that emerged in April 2025. Gunra operates as a ransomware-as-a-service (RaaS), allowing affiliates to target various organizations globally. It employs a double-extortion model, encrypting data and threatening to publish exfiltrated information on a dedicated leak site. Key sectors at risk include government, critical infrastructure, healthcare, and financial services. The advisory's primary authoring agencies are the FBI, CISA, and other international cybersecurity entities. They recommend prioritizing patching internet-facing vulnerabilities, implementing robust offline backups, and segmenting networks. Gunra actors gain initial access by exploiting vulnerabilities in VPN gateways and RDP-exposed infrastructure. They leverage Impacket libraries for lateral movement and utilize credential dumping techniques to escalate privileges. The ransomware uses native OS APIs for execution and encryption. Gunra actors also attempt to evade detection by deleting logs and clearing command history. The binary includes anti-debugging features to hinder analysis. Organizations are urged to implement the provided technical guidance to protect against Gunra attacks.