FBI, CISA, and international cybersecurity agencies have issued a joint advisory regarding the Gunra ransomware group, a rapidly expanding Ransomware-as-a-Service (RaaS) operation that has set its sights on critical infrastructure sectors including government, energy, and healthcare.
The Gunra variant first appeared in mid-2025 and transitioned to a formal RaaS model in early 2026, providing affiliates with a management panel and a configurable builder for cross-platform encryption. This expansion has led to a surge in activity, with the group’s dedicated leak site now listing at least 14 confirmed victims across Brazil, Canada, Turkey, South Korea, Taiwan, and the United States.
Double Extortion and Rapid Encryption
The group employs a aggressive double-extortion model, both encrypting victim data and threatening to publish exfiltrated information if a ransom is not paid. A notable breach at a Dubai hospital resulted in the exposure of approximately 40 terabytes of sensitive data, illustrating the scale of their exfiltration capabilities.
Technically, the Gunra ransomware is designed for speed. The Windows variant appends the .ENCRT extension to files and drops a ransom note named R3ADM3.txt. It utilizes advanced obfuscation and anti-debugging techniques to evade detection while rapidly traversing file systems to maximize damage before remediation can begin.
Critical Flaw in Linux Variant
Interestingly, researchers from Breakglass Intelligence identified a significant weakness in Gunra’s Linux-targeted variant. The encryption keys rely on a weak pseudorandom number generator seeded with the predictable system time (time(NULL)). This flaw allows for the recovery of encrypted files without paying the ransom, though the group continues to use the variant for high-impact strikes on server environments.
The advisory underscores the growing threat of ransomware targeting operational technology (OT) and critical infrastructure. Agencies recommend the immediate implementation of multi-factor authentication, rigorous monitoring for shadow-copy deletion, and the use of updated threat intelligence to block known Tor-based leak sites.
Sources: CISA; FBI; PolySwarm; Breakglass Intelligence
discussion