Gunra ransomware CVE exploitation and double-extortion activity
Malware Activity
Summary
Hide ▲
Show ▼
Gunra ransomware is an RaaS operation targeting government and critical national infrastructure organizations, with a joint US/Republic of Korea advisory warning that affiliates exploit CVE-2024-55591 and CVE-2025-24472 in FortiOS/FortiProxy to gain initial access. After entry, the group uses stolen credentials, MFA bypass, OpenSSH, and other persistence and lateral-movement techniques to reach Microsoft 365 data and carry out double extortion. The advisory says victims can face Tor-based publication threats if they do not engage within five to seven days and reports ransom demands that start in the tens of millions of dollars.
Related Happenings
Gunra launches RaaS affiliate program and recruits initial access brokers
Threat Actor Meta
H score32
First: 11.08.2026 12:47
Last: 11.08.2026 12:47
Sources 1
How related:
In early 2026, the group developed a structured RaaS affiliate program advertised on dark web forums.
About this happening:
Gunra expanded its criminal operating model in January 2026 by launching a ransomware-as-a-service (RaaS) platform and recruiting initial access brokers. The group...
Gunra launches RaaS affiliate program and recruits initial access brokers
Threat Actor MetaHow related: In early 2026, the group developed a structured RaaS affiliate program advertised on dark web forums.
About this happening: Gunra expanded its criminal operating model in January 2026 by launching a ransomware-as-a-service (RaaS) platform and recruiting initial access brokers. The group...
Gunra ransomware mitigation advisory (CISA/FBI/partners)
Advisory/Mitigation
H score26
First: 10.08.2026 15:00
Last: 10.08.2026 15:00
Sources 1
How related:
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world.
About this happening:
Gunra ransomware is the focus of a joint advisory from CISA, FBI, DC3, NSA, USSS, and KNPA warning critical infrastructure organizations worldwide. The advisory sa...
Gunra ransomware mitigation advisory (CISA/FBI/partners)
Advisory/MitigationHow related: Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world.
About this happening: Gunra ransomware is the focus of a joint advisory from CISA, FBI, DC3, NSA, USSS, and KNPA warning critical infrastructure organizations worldwide. The advisory sa...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
Campaign
H score34
First: 29.07.2026 20:54
Last: 29.07.2026 20:54
Sources 1
About this happening:
The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
CampaignAbout this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
Identity-based access becomes the leading ransomware initial-access trend in 2026
Trend
H score28
First: 15.07.2026 15:45
Last: 15.07.2026 15:45
Sources 1
About this happening:
Identity-based attacks became the leading ransomware initial-access trend, raising the risk of credential abuse and legitimate login misuse across affected networks. S...
Identity-based access becomes the leading ransomware initial-access trend in 2026
TrendAbout this happening: Identity-based attacks became the leading ransomware initial-access trend, raising the risk of credential abuse and legitimate login misuse across affected networks. S...
Helix vishing and SharePoint data-extortion campaign
Campaign
H score38
First: 09.07.2026 20:08
Last: 09.07.2026 20:08
Sources 1
About this happening:
The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Helix vishing and SharePoint data-extortion campaign
CampaignAbout this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Timeline
-
10.08.2026 15:00 4 articles · 13d ago
CISA and partners warn on Gunra ransomware exploiting CVE-2024-55591 and CVE-2025-24472
Initial DisclosureCISA, FBI, DC3, NSA, USSS, and KNPA released a joint Cybersecurity Advisory on Gunra ransomware, describing it as a ransomware-as-a-service variant used by affiliates to target critical infrastructure sectors and organizations worldwide, including healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. The advisory says Gunra actors gain initial access by exploiting CVE-2024-55591 and CVE-2025-24472 in internet-facing devices, then use double extortion with data exfiltration, data encryption, and Tor-based publication threats if the victim does not pay the ransom within five to seven days.
Show sources
- CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors — www.cisa.gov — 10.08.2026 15:00
- CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors — www.cisa.gov — 10.08.2026 15:00
- Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks — thehackernews.com — 11.08.2026 12:16
- Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure — www.infosecurity-magazine.com — 12.08.2026 16:15