CISA’s #StopRansomware advisory covers Gunra, a ransomware-as-a-service operation that emerged as a variant in 2025 and expanded to affiliate-driven RaaS in 2026. Gunra affiliates target government, critical infrastructure, and other organizations using a double-extortion model, encrypting data and threatening to leak stolen information on a dedicated leak site.
From an identity and AD perspective, the advisory’s key mitigations are notable: attackers gain footholds through internet-facing access points like VPN gateways and RDP-exposed systems, then move laterally across the network. CISA recommends patching known exploited vulnerabilities in these access layers, network segmentation to limit lateral movement, and offline immutable backups.
What to take away: Gunra’s playbook hinges on compromised remote access and unchecked lateral movement — both fundamentally identity problems. Hardening VPN/RDP authentication, enforcing MFA, tiering privileged accounts, and segmenting AD trust paths directly disrupt the intrusion chain before ransomware detonates.