
Gunra Ransomware Builds a New Attack Network Through RaaS
Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met.
The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant derived from leaked Conti ransomware source code.
Gunra Ransomware Shifts to Affiliate Model
dark web forums.
The program provides affiliates with a management panel, configurable ransomware builder, cr...