← Knowledge Center
Advisory

CISA Advisory: Gunra RaaS Exploits VPN/RDP Access for Double Extortion

CISA’s #StopRansomware advisory covers Gunra, a ransomware-as-a-service operation that emerged as a variant in 2025 and expanded to affiliate-driven RaaS in 2026. Gunra affiliates target government, critical infrastructure, and other organizations using a double-extortion model, encrypting data and threatening to leak stolen information on a dedicated leak site.

From an identity and AD perspective, the advisory’s key mitigations are notable: attackers gain footholds through internet-facing access points like VPN gateways and RDP-exposed systems, then move laterally across the network. CISA recommends patching known exploited vulnerabilities in these access layers, network segmentation to limit lateral movement, and offline immutable backups.

What to take away: Gunra’s playbook hinges on compromised remote access and unchecked lateral movement — both fundamentally identity problems. Hardening VPN/RDP authentication, enforcing MFA, tiering privileged accounts, and segmenting AD trust paths directly disrupt the intrusion chain before ransomware detonates.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.