CISA: Gunra recruits pentesters as initial access brokers for ransomware
CISA advisory AA26-222A, published on 10 August 2026, describes Gunra as a commercial ransomware-as-a-service operation derived from leaked Conti 1 source code. The group recruits penetration testers and ethical hackers as initial access brokers, paying them a share of ransom profits for enterprise network access.
- Gunra emerged in April 2025 from leaked Conti 1 source code
- In early 2026 it launched an affiliate RaaS programme on dark web forums
- Brokers are paid a share of ransom profits for enterprise network access
- Priority patching targets VPN and RDP flaws CVE-2024-55591 and CVE-2025-24472
Read next
Security