Healthcare Orgs Warned About Gunra Ransomware Attacks
CISA, the FBI, and international partners have issued a joint cybersecurity advisory about the Gunra ransomware-as-a-service (RaaS) operation, which is targeting government and critical infrastructure entities, including healthcare organizations, and organizations in other sectors. The group has conducted attacks in the Americas, Europe, Middle East, Africa, and Asia-Pacific, with attacks accelerating in 2026.
Gunra ransomware was first identified as a financially motivated threat group in April 2025; however, in 2026, it transitioned into a RaaS group. The group is attempting to recruit experienced affiliates from other groups by offering an 80% cut of any generated ransoms, as well as initial access brokers who can deliver enterprise-scale footholds.
The group primarily targets Windows systems and uses advanced encryption methods. In late 2025, the group also developed a Linux variant of its encryptor to allow cross-platform targeting. The encryptor is based on leaked Conti ransomware source code. The group engages in double extortion attacks, stealing sensitive data before encrypting files. After file encryption, victims receive a ransom note in each affected directory and are required to initiate negotiations via a Tor-based negotiation panel. Victims are provided with unique login credentials to access the negotiation panel and are given between 5 and 10 days to commence negotiations.
The group has been observed gaining access to victims’ networks by exploiting known vulnerabilities in Internet-facing devices, including firewalls and VPN appliances, such as the CVE-2024-55591 and CVE-2025-24472 authentication bypass vulnerabilities in FortiOS/FortiProxy. The group has also been observed exploiting Secure Shell (SSH) access control vulnerabilities in internet-facing VPN gateways.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Multiple stealth and defense impairment techniques are used to hinder detection and analysis. Data collected and exfiltrated includes business-critical documents, databases, personally identifiable information (PII), and internal email communications, including from Microsoft OneDrive and SharePoint. The stolen data is used as leverage to pressure victims into paying the ransom. Threats are issued to publish or sell the stolen data on a dedicated dark web data leak site if the ransom is not paid. The group’s data leak site currently lists more than 30 worldwide victims.
The #StopRansomware cybersecurity advisory recommends taking immediate action to reduce the risk of an attack, including prioritizing patching for known exploited vulnerabilities, especially vulnerabilities in VPNs and RDP-exposed infrastructure. Networks should be segmented to hamper lateral movement from initially compromised devices to other organizational systems, and immutable backups should be created and stored in physically separate, segmented locations to ensure data can be recovered without paying the ransom.
Full details of the group’s tactics, techniques, and procedures (TTPs), Indicators of Compromise (IoC), and recommended mitigations are detailed in the cybersecurity advisory.


