CISA, FBI Warn Gunra Ransomware Actors Targeting Critical Infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation, Department of Defense Cyber Crime Center (DC3), National Security Agency, and U.S. Secret Service released a joint Cybersecurity Advisory, #StopRansomware: Gunra Ransomware.

The advisory details Gunra ransomware, a ransomware-as-a-service (RaaS) variant used by affiliates to target a range of critical infrastructure sectors and organizations worldwide — including healthcare and public health, financial services, government services and facilities, and professional and nonprofit services.

Gunra actors gain initial access by exploiting common vulnerabilities and exposures (CVEs) CVE-2024-55591 and CVE-2025-24472 in internet-facing devices. With access, Gunra actors use a double-extortion model that employs both data exfiltration and data encryption, and negotiate through a Tor-based portal, where they threaten to publish exfiltrated data if the victim does not pay the ransom within five to seven days. The advisory provides tailored detection guidance, indicators of compromise (IOCs), recommended actions if potential compromise is detected, and mitigation recommendations aligned to Cross-Sector Cybersecurity Performance Goals (CPGs).

“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations. To combat cyber threat activity, CISA continues to work with our government, industry and international partners to provide timely and actionable information that reduces the prevalence of damaging ransomware incidents,” said CISA Acting Executive Assistant Director for Cybersecurity, Chris Butera. “With our partners, CISA encourages organizations to urgently mitigate vulnerabilities identified in this advisory, implement recommended actions, and adopt security measures aligned to CPGs.”

To protect against Gunra ransomware, CISA and partners provide several mitigation recommendations in the advisory including:

  • Keep all operating systems, software, and firmware up to date.
  • Prioritize patching known exploited vulnerabilities in internet-facing systems.
  • Ensure backups are immutable, stored in a physically separate, segmented location, and tested offline.
  • Segment networks. This prevents threat actors from using an initially compromised device to move laterally to other systems in the organization.

The original announcement can be found here.

The Government Technology & Services Coalition's Homeland Security Today (HSToday) is the premier news and information resource for the homeland security community, dedicated to elevating the discussions and insights that can support a safe and secure nation. A non-profit magazine and media platform, HSToday provides readers with the whole story, placing facts and comments in context to inform debate and drive realistic solutions to some of the nation’s most vexing security challenges.

Related Articles

Latest Articles