WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Defense Cyber Crime Center (DC3), National Security Agency (NSA), U.S. Secret Service (USSS), and Republic of Korea’s National Policy Agency (KNPA) released a joint Cybersecurity Advisory, #StopRansomware: Gunra Ransomware, a ransomware-as-a-service (RaaS) variant used by affiliates to target a range of critical infrastructure sectors and organizations worldwide—including healthcare and public health, financial services, government services and facilities, and professional and nonprofit services.
Gunra actors gain initial access by exploiting common vulnerabilities and exposures (CVEs) CVE-2024-55591 and CVE-2025-24472 in internet-facing devices. With access, Gunra actors use a double-extortion model that employs both data exfiltration and data encryption, and negotiate through a Tor-based portal, where they threaten to publish exfiltrated data if the victim does not pay the ransom within five to seven days. The advisory provides tailored detection guidance, indicators of compromise (IOCs), recommended actions if potential compromise is detected, and mitigation recommendations aligned to Cross-Sector Cybersecurity Performance Goals (CPGs).
“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations. To combat cyber threat activity, CISA continues to work with our government, industry and international partners to provide timely and actionable information that reduces the prevalence of damaging ransomware incidents,” said CISA Acting Executive Assistant Director for Cybersecurity, Chris Butera. “With our partners, CISA encourages organizations to urgently mitigate vulnerabilities identified in this advisory, implement recommended actions, and adopt security measures aligned to CPGs.”
To protect against Gunra ransomware, CISA and partners provide several mitigation recommendations in the advisory including:
- Keep all operating systems, software, and firmware up to date.
- Prioritize patching known exploited vulnerabilities in internet-facing systems.
- Ensure backups are immutable, stored in a physically separate, segmented location, and tested offline.
- Segment networks. This prevents threat actors from using an initially compromised device to move laterally to other systems in the organization.
For more information, please visit Stop Ransomware.
###
About CISA
As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to manage, uncover, and reduce risk to our digital and physical infrastructure Americans rely on every hour of every day.
Visit CISA.gov for more information and follow us on X, Facebook, LinkedIn, Instagram.
