On 10 August 2026, CISA, FBI, DC3, NSA, USSS and KNPA released joint advisory #StopRansomware AA26-222A on Gunra — a Conti-derived RaaS with Windows and Linux variants (Linux up to 100 encryption threads) and double extortion. For NIS2 essential/important entities this means three obligations: offline immutable backups, patching known exploited VPN/RDP vulnerabilities, and 24/72-hour reporting via the national CSIRT. We are not a 24/7 SOC, we do not issue legal opinions, we do not declare NIS2/KSC compliance. Below: facts versus conclusions, a 30/90-day plan, and where CHORS.NET can help.
Key facts
- Source and date. Joint Cybersecurity Advisory AA26-222A was published on 10 August 2026 by CISA, FBI, DC3, NSA, USSS and KNPA (Korea National Police Agency). There is no Polish-language version; this is an English-language operational document for IR/IT/OT specialists [1][2].
- Origin and taxonomy. Gunra is a RaaS descended from the leaked Conti 1 source code. The lineage was first observed in April 2025; from early 2026 the programme has been formalised and recruits affiliates via dark web forums [1][3][5].
- Vectors and technique. The Linux variant allows operators to configure up to 100 encryption threads and supports partial encryption; the Windows variant preserves the original mass-encryption behaviour. The infection chain leverages exploitation of known VPN/RDP vulnerabilities, lateral movement, privilege escalation and pre-encryption exfiltration (double extortion) [3][4][5].
- Sector and geography. Victims have been observed in the Americas, Europe, the Middle East, Africa and Asia-Pacific. Sectors include healthcare, financial services, critical manufacturing, transport/logistics, utilities, government services, academia, retail, professional/nonprofit [1][2].
- Early public victims. Actors linked to Gunra leaked 40 TB of data from American Hospital Dubai, including medical records and payment card data; a claimed leak of 450 million patient records remains under independent verification [3][6].
- IOCs and TTPs. Full indicators of compromise were published in STIX 2.x (XML/JSON) as an attachment to the advisory [1][2].
- CISA recommendations. (a) Patch known exploited VPN/RDP vulnerabilities (see CISA KEV); (b) offline, immutable backups in a segmented location; (c) network segmentation (particularly IT/OT); (d) RDP hardening (no internet exposure, mandatory MFA); (e) test restore procedures at least quarterly [1][2].
- NIS2 implication for EU operators. Essential/important entities hit by a qualifying incident trigger 24-hour early warning and 72-hour notification under art. 23 NIS2; BCP/DR obligations flow from art. 21(2)(c) (continuity) and art. 21(2)(d) (supply chain, including assessment of RMM/VPN providers) [7][8].
- Sources (7). CISA AA26-222A [1], CISA/DoD PDF [2], Trend Micro research [3], DarkReading [4], CSO Online [5], Cybersecuritynews.com [6], EC NIS2 directive page [7], NIS2-templates.com 24h trigger [8].
Methodology note: facts tagged [1][2] come from the official advisory (class A). Operational conclusions (NIS2 mapping, 30/90-day plan) are CHORS recommendations and are not part of the advisory. Recommendations for a specific firm require that firm's own context (segment, suppliers, exposure) — we do not publish generic one-size-fits-all checklists.
Decision table: what we know → what it means for B2B/manufacturing → what to do
| Area | What we know (facts from advisory + research) | What it means for a B2B / manufacturing firm | Recommended 30-day action | Recommended 90-day action |
|---|---|---|---|---|
| VPN/RDP | CISA explicitly lists patching known exploited VPN/RDP as action #1 [1][2] | NIS2 entities with public RDP/VPN are exposed to RaaS affiliate initial access | Inventory public RDP/VPN; disable where unjustified; MFA for the rest; priority patch from CISA KEV | Authorized Vulnerability Assessment and/or Passive Exposure Snapshot to detect shadow VPN/RDP |
| Backups | Offline, immutable backups in a segmented location [1][2] | Without them, post-encryption recovery forces a „pay or cease to operate" decision | Audit 3-2-1 (3 copies, 2 media, 1 offline/offsite); restore test of one critical machine; immutability (WORM/S3 Object Lock) | Continuous restore testing; automation of RPO/RTO; AD/IdP-isolated backup segment |
| Lateral movement / IT-OT | Gunra uses up to 100 threads for Windows and Linux encryption [3][4] | Shared AD/IdP domains and IT-OT bridges are classical vectors for manufacturers | Map Tier-0/Tier-1/Tier-2; VLAN segmentation; PAW-only service accounts; alert on anomalous remote sessions | Full Purdue model + jump-host deployment; passive monitoring on the IT/OT boundary (no active OT scanning) |
| IT supply chain | Affiliates target RMM/VPN/IT-services suppliers [1][3] | Manufacturers using MSPs or sharing admin tooling carry indirect exposure | Inventory suppliers with AD/IdP/VPN access; review contracts for security obligations; rotate credentials | Vendor Risk Management aligned with P3 NIS2/KSC Readiness (art. 21(2)(d)); periodic supplier audits |
| NIS2 reporting (art. 23) | 24-hour early warning from moment of „becoming aware" of a potential significant incident; 72-hour full notification [7][8] | The 24-hour clock starts very early; absent procedure = delay + loss of regulator trust | Refresh the incident playbook; appoint a contact for the national CSIRT; early-warning template | Quarterly tabletop exercise (ransomware simulation); established communication channels (email + phone) with the national CSIRT |
| Data exfiltration (DLS) | Double extortion: Tor negotiation portal + dedicated leak site [1][3] | Even after backup recovery, data may already be published; GDPR/UODO consequences, reputational loss | Identify data classes (personal data, sensitive data); DLP baseline; „when DLS publishes" procedure | Extended DLP; data retention and minimisation; crisis communication plan for customers/regulator |
| AI-assisted context (note) | Many RaaS families now rely on speed and automation; Gunra emphasises speed (100 threads) [3] | Time from initial access to full encryption is shorter than human reaction; detection must be automated | Tune EDR for MITRE ATT&CK TTPs (TA0008/TA0010); automatic lateral-movement cut-off on alerts | EDR + SIEM/SOAR integration; auto-isolation playbooks; quarterly threat hunting |
Operator perspective: Marcin Białczyk (CHORS.NET)
Scale and speed in Gunra are not accidental design choices — they reflect a simple calculation: how many minutes pass from the first lateral-movement event to the moment when backup cannot keep up with restore, while 100 threads encrypt everything that is not offline. In my operational practice I see that organisations that do not invest in immutable backups in a separated location effectively take the decision „pay or cease to exist" long before the first incident. A backup that cannot be quickly restored is not a backup — it is an archive. In the benchmarks I run for clients, we target full restore of a single critical machine (DC/IdP) in under 2 hours and a full-environment test restore at least quarterly. If you do not do this, you do not know whether you have a backup — you only know you have a copy of it.
The second axis I treat as priority is VPN/RDP exposure. The joint advisory names it as the first action point, because Gunra affiliates hunt publicly exposed RDP and unpatched VPN endpoints — this is not „theory", it is the daily reality of the initial access broker (IAB) market. Within our Passive Exposure Snapshot (P0), we show the client which of their endpoints and tunnels actually „shine" in OSINT and public registries, without active contact with the infrastructure. It is the same model we use when assessing MSP and RMM suppliers under P3 NIS2/KSC Readiness. Where we see public RDP with 2019-vintage firmware, the recommendation is binary: switch it off or rebuild it — there is no „let's wait a bit" option.
The third axis, equally important for manufacturers and IT/OT integrators, is awareness that Gunra has a Linux variant capable of 100 threads. This is not „the same ransomware, just on servers" — it is a signal that containers, hypervisors and databases are now in the affiliates' field of interest exactly as much as the file server. In our P2 (On-site / Extended Assessment) reports I treat the IT/OT segment as a zone where active methods are prohibited (policy 02, section 4, stop conditions), but where passive evidentiary support and configuration hardening are mandatory. If your organisation runs a production segment, do not ask „do we have backups" — ask „are the production backups immutable and separated from AD". That is the difference between a week-long production stop and months-long operational loss.
(case study placeholder, e.g. „FMCG manufacturer, 800 endpoints, public RDP 24/7; after P0 + P3 readiness consultation, exposure closed in 18 days, immutable backup deployed in 60 days; full test restore completed in 92 days from the audit."). Without a real case, no fabrication.
Frequently asked questions
Can my company be directly attacked by Gunra even if we are not in government or critical infrastructure?
Yes — Gunra affiliates target multiple sectors, including manufacturing, logistics, retail, healthcare, finance and professional services. Sector is not the filter; the filter is whether you have publicly exposed VPN/RDP and/or an RMM supplier with unpatched vulnerabilities.
Does CHORS.NET issue an NIS2 certificate or declare full compliance as a result of this article?
No. CHORS.NET does not certify NIS2/KSC compliance and does not issue standalone legal opinions; we are not a 24/7 SOC and we do not guarantee detection of every incident. We collaborate with law firms on legal interpretation and support clients under P3 NIS2/KSC Readiness (gap assessment, control matrix, evidence pack).
What does „offline, immutable backup in a segmented location" actually mean in practice?
(1) A copy physically or logically separated from AD/IdP (e.g. a service account with minimal scope, no inherited permissions); (2) immutability (Object Lock, WORM, write-once media or air-gapped NAS); (3) restore test of one critical machine at least quarterly with measured time-to-restore. Merely having a backup without a restore test is insufficient.
Should I report an incident to the national CSIRT even on suspicion only?
Under NIS2, the 24-hour early-warning clock starts at the moment of becoming aware of a potential significant incident — that is a deliberately low bar. In practice: if you see anomalous behaviour (file encryption, login from an atypical location, DLS mention), do not wait for a full forensic analysis — send the early warning via the national CSIRT portal and complete within 72 hours. Legal interpretation requires consultation with a law firm.
What should I do immediately if I already see encrypted files and a ransom demand?
(1) Isolate affected hosts (disconnect from the network, do not power off); (2) preserve logs (memory, disk, EDR telemetry); (3) appoint an internal contact and trigger escalation; (4) send early warning to the national CSIRT within 24 hours; (5) do not pay the ransom without an impact analysis and without consulting a law firm and the relevant authority — in some jurisdictions payment may breach sanctions; (6) trigger the crisis communication plan for customers/partners.
Does CHORS.NET run „pentests" or „penetration tests" as a standard offering?
In our nomenclature (P1 — Authorized Vulnerability Assessment, with the Exposure Validation component) we run authorised validation within an agreed scope (AtT + RoE + manifest), never without a signed package and capability tokens. We do not use „pentest" as a trade name — the term is too imprecise under policy 02 and the global prohibitions (exploitation, brute force, DoS, persistence). Full scope is described at /uslugi/.
How CHORS.NET helps
CHORS.NET supports the technical-operational side: passive exposure assessment, configuration verification, evidence packs and NIS2/KSC readiness support. See: Services, About CHORS.NET and Contact.
Boundaries and assumptions
- We are not a 24/7 SOC and we do not guarantee detection of every incident. This article describes a class of risk and a general framework — it is not a detection service.
- We do not certify NIS2/KSC compliance and we do not issue standalone legal opinions. On legal interpretation we collaborate with law firms.
- Results reflect the state of the art on 2026-08-10. Ransomware families evolve (Linux/Windows variants, TTPs, IOCs); recommendations require at least quarterly review.
- We do not provide generic one-size-fits-all checklists. Every 30/90-day plan requires a specific firm's context: NIS2 segment classification, exposure (public RDP/VPN/RMM), MSP suppliers, data classification, IT/OT topology.
- This article is informational and technical. It is not legal advice or an investment recommendation.
- For interpretation of NIS2/KSC (art. 21, art. 23) we refer to counsel. The article references above are framework-level and require legal verification against the specific facts.
- In OT/ICS we apply a passive approach. We do not actively scan PLC/HMI/SCADA; our P2 support is passive evidentiary support and configuration hardening.
Sources
- CISA AA26-222A — #StopRansomware: Gunra Ransomware (joint advisory FBI/CISA/DC3/NSA/USSS/KNPA)
- CISA #StopRansomware — joint advisories and operational resources
- Trend Micro Research — Gunra Ransomware Group Unveils Efficient Linux Variant
- Dark Reading — Nimble "Gunra" Ransomware Evolves With Linux Variant
- CSO Online — Ransomware upstart Gunra goes cross-platform with encryption upgrades
- Cybersecurity News — Gunra Ransomware Expands RaaS Operations
- European Commission — NIS2 Directive (2022/2555)
- NIS2 Article 23 — incident reporting obligations (24h/72h) — EUR-Lex