NSA joins FBI and others in releasing guidance to defend against Gunra Ransomware

NSA

The National Security Agency (NSA) has joined the Federal Bureau of Investigation (FBI) and others in releasing a joint Cybersecurity Advisory, “#StopRansomware: Gunra Ransomware,” as an ongoing effort to publish information about ransomware variants and threat actors.

This includes sharing recently and historically observed tactics, techniques, procedures, and indicators of compromise to help organisations defend networks from ransomware. 

Gunra is a ransomware-as-a-service (RaaS) program used by affiliates to target government, critical infrastructure, and other organisations worldwide, including in the U.S. NSA states that the Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026.

The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site and sell it if the ransom is not paid. 

According tot he NSA, Gunra employs multiple stealth and defence impairment techniques to hinder detection and analysis. While active within victim networks, Gunra actors typically attempt to mask their presence by deleting system/network access logs and clearing command history.

Also, prior to data encryption, Gunra actors collect sensitive victim data. The FBI observed actors collecting files from victims that included business-critical documents, databases, personally identifiable information, and internal email communications.

Victims span organisations in the Americas, Europe, Middle East, Africa, and Asia-Pacific across multiple sectors including healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities, utilities, academia, media and communications, retail and professional and nonprofit services.

Cybersecurity architects, defensive cybersecurity analysts, vulnerability analysts, systems administrators, security systems managers, and other net defenders are advised to implement the recommended mitigations and validate their security controls: prioritising patching known exploited vulnerabilities; implementing and testing offline, immutable backups; and segmenting networks.

In the event of a potential compromise, the NSA guidance also outlines recommended incident response procedures.

To read more security news, click here.

Share this

Related News

From July 1, 2026 Redvision CCTV renews its agreement…

News

dormakaba will showcase its latest security solutions at HITEC…

News

dormakaba has acquired Airsphere GmbH (“Airsphere”). Airsphere is an…

News

Scroll to Top