Find notable cyber news and cases, enriched with sources, timelines, and signals.

Gunra ransomware CVE exploitation and double-extortion activity

Malware Activity
First reported
Last updated
Happening score
H score 26
3 unique sources, 3 articles

Summary

Hide ▲

Gunra ransomware is an RaaS operation targeting government and critical national infrastructure organizations, with a joint US/Republic of Korea advisory warning that affiliates exploit CVE-2024-55591 and CVE-2025-24472 in FortiOS/FortiProxy to gain initial access. After entry, the group uses stolen credentials, MFA bypass, OpenSSH, and other persistence and lateral-movement techniques to reach Microsoft 365 data and carry out double extortion. The advisory says victims can face Tor-based publication threats if they do not engage within five to seven days and reports ransom demands that start in the tens of millions of dollars.

Related Happenings

Gunra launches RaaS affiliate program and recruits initial access brokers

Threat Actor Meta
H score32 First: 11.08.2026 12:47 Last: 11.08.2026 12:47 Sources 1

How related: In early 2026, the group developed a structured RaaS affiliate program advertised on dark web forums.

About this happening: Gunra expanded its criminal operating model in January 2026 by launching a ransomware-as-a-service (RaaS) platform and recruiting initial access brokers. The group...

Gunra ransomware mitigation advisory (CISA/FBI/partners)

Advisory/Mitigation
H score26 First: 10.08.2026 15:00 Last: 10.08.2026 15:00 Sources 1

How related: Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world.

About this happening: Gunra ransomware is the focus of a joint advisory from CISA, FBI, DC3, NSA, USSS, and KNPA warning critical infrastructure organizations worldwide. The advisory sa...

ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations

Campaign
H score34 First: 29.07.2026 20:54 Last: 29.07.2026 20:54 Sources 1

About this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...

Identity-based access becomes the leading ransomware initial-access trend in 2026

Trend
H score28 First: 15.07.2026 15:45 Last: 15.07.2026 15:45 Sources 1

About this happening: Identity-based attacks became the leading ransomware initial-access trend, raising the risk of credential abuse and legitimate login misuse across affected networks. S...

Helix vishing and SharePoint data-extortion campaign

Campaign
H score38 First: 09.07.2026 20:08 Last: 09.07.2026 20:08 Sources 1

About this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...

Timeline

  1. 10.08.2026 15:00 4 articles · 13d ago

    CISA and partners warn on Gunra ransomware exploiting CVE-2024-55591 and CVE-2025-24472

    Initial Disclosure

    CISA, FBI, DC3, NSA, USSS, and KNPA released a joint Cybersecurity Advisory on Gunra ransomware, describing it as a ransomware-as-a-service variant used by affiliates to target critical infrastructure sectors and organizations worldwide, including healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. The advisory says Gunra actors gain initial access by exploiting CVE-2024-55591 and CVE-2025-24472 in internet-facing devices, then use double extortion with data exfiltration, data encryption, and Tor-based publication threats if the victim does not pay the ransom within five to seven days.

    Show sources