CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors
U.S. agencies and South Korea’s police issued a joint advisory warning of the Gunra ransomware threat to critical infrastructure sectors, citing double extortion tactics and specific CVEs used for initial access.
The Cybersecurity and Infrastructure Security Agency (CISA), FBI, NSA, and other partners released a joint advisory on Gunra ransomware, a RaaS variant targeting critical infrastructure sectors such as healthcare, finance, and government services. The advisory highlights that Gunra affiliates exploit known vulnerabilities in internet-facing devices to gain initial access before deploying a double-extortion model involving both data encryption and theft. Affected organizations are urged to review the advisory for tailored detection guidance and indicators of compromise to identify potential intrusions promptly.
The advisory specifies that Gunra actors negotiate ransom demands through a Tor-based portal, imposing a five-to-seven-day deadline for payment under threat of publishing exfiltrated data. It provides recommended actions for organizations if compromise is suspected, including isolating affected systems and preserving evidence. The guidance aligns with the Cross-Sector Cybersecurity Performance Goals (CPGs) to strengthen baseline security measures across sectors. CISA emphasizes the urgency of addressing the identified vulnerabilities to mitigate the risk of ransomware incidents.
CISA Acting Executive Assistant Director for Cybersecurity, Chris Butera, stated that Gunra represents an ongoing trend of disruptive ransomware attacks affecting U.S. and international organizations. The advisory reflects a collaborative effort among U.S. agencies and South Korea’s National Policy Agency to provide actionable intelligence and reduce the impact of ransomware campaigns. Organizations are encouraged to implement the recommended mitigations and adopt security measures aligned with CPGs to enhance resilience against ransomware threats.
The advisory corrects an earlier error linking to CVE-2024-5559, clarifying that the relevant vulnerabilities are CVE-2024-55591 and CVE-2025-24472. As the nation’s cyber defense agency, CISA leads efforts to manage and reduce risks to critical infrastructure. Organizations are directed to visit the Stop Ransomware website for additional resources and guidance on mitigating Gunra ransomware threats.