Gunra ransomware mitigation advisory (CISA/FBI/partners)
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Gunra ransomware is the focus of a joint advisory from CISA, FBI, DC3, NSA, USSS, and KNPA warning critical infrastructure organizations worldwide. The advisory says the RaaS operation first emerging in April 2025 and tied to leaked Conti source code gains initial access by exploiting CVE-2024-55591 and CVE-2025-24472 in Fortinet FortiOS/FortiProxy devices. It also says Gunra actors use stolen credentials, MFA bypass, OpenSSH, and Microsoft 365 exfiltration to move laterally, steal data, and pressure victims with double extortion. The advisory recommends patching exposed systems, limiting lateral movement, and maintaining immutable backups while it provides detection guidance and IOCs.
Related Happenings
Gunra launches RaaS affiliate program and recruits initial access brokers
Threat Actor Meta
H score32
First: 11.08.2026 12:47
Last: 11.08.2026 12:47
Sources 1
How related:
In early 2026, the group developed a structured RaaS affiliate program advertised on dark web forums.
About this happening:
Gunra expanded its criminal operating model in January 2026 by launching a ransomware-as-a-service (RaaS) platform and recruiting initial access brokers. The group...
Gunra launches RaaS affiliate program and recruits initial access brokers
Threat Actor MetaHow related: In early 2026, the group developed a structured RaaS affiliate program advertised on dark web forums.
About this happening: Gunra expanded its criminal operating model in January 2026 by launching a ransomware-as-a-service (RaaS) platform and recruiting initial access brokers. The group...
Gunra ransomware CVE exploitation and double-extortion activity
Malware Activity
H score26
First: 10.08.2026 15:00
Last: 10.08.2026 15:00
Sources 1
How related:
Gunra ransomware actors are exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organizations, a joint advisory issued by US and Republic of Korea authorities has warned.
About this happening:
Gunra ransomware is an RaaS operation targeting government and critical national infrastructure organizations, with a joint US/Republic of Korea advisory warni...
Gunra ransomware CVE exploitation and double-extortion activity
Malware ActivityHow related: Gunra ransomware actors are exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organizations, a joint advisory issued by US and Republic of Korea authorities has warned.
About this happening: Gunra ransomware is an RaaS operation targeting government and critical national infrastructure organizations, with a joint US/Republic of Korea advisory warni...
Clop Internet-exposed Windchill and FlexPLM data theft extortion campaign
Campaign
H score55
First: 24.07.2026 10:36
Last: 24.07.2026 10:36
Sources 1
About this happening:
The Clop/Cl0p campaign against PTC Windchill and FlexPLM now includes a bespoke JSP web shell tied to CVE-2026-12569. ReliaQuest said the implant is built to dec...
Clop Internet-exposed Windchill and FlexPLM data theft extortion campaign
CampaignAbout this happening: The Clop/Cl0p campaign against PTC Windchill and FlexPLM now includes a bespoke JSP web shell tied to CVE-2026-12569. ReliaQuest said the implant is built to dec...
Latest development: 18.08.2026 20:29
A custom Java web shell designed for PTC Windchill and FlexPLM servers was likely deployed in recent data theft attacks exploiting CVE-2026-12569, and it includes built-in features to decrypt credentials, enumerate file repositories, and steal files. The implant uses X-windchill-req control messages, imports Windchill-specific classes such as MethodContext, WTConnection, and WTKeyStoreUtil, and appears to be an application-specific evolution of Clop's mass-exploitation playbook.
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionAbout this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...
CISA-led joint advisory on Russian router targeting
Public Sector Action
H score32
First: 14.07.2026 15:00
Last: 14.07.2026 15:00
Sources 1
About this happening:
CISA and partner agencies released a joint cybersecurity advisory warning that Russian state-sponsored actors are targeting vulnerable networking devices in crit...
CISA-led joint advisory on Russian router targeting
Public Sector ActionAbout this happening: CISA and partner agencies released a joint cybersecurity advisory warning that Russian state-sponsored actors are targeting vulnerable networking devices in crit...
Timeline
-
10.08.2026 15:00 5 articles · 13d ago
CISA, FBI, DC3, NSA, USSS, and KNPA warn on Gunra ransomware
Initial DisclosureCISA, FBI, DC3, NSA, USSS, and KNPA released a joint Cybersecurity Advisory, #StopRansomware: Gunra Ransomware, warning that Gunra ransomware affiliates target critical infrastructure sectors worldwide, including healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. The advisory says Gunra actors gain initial access by exploiting CVE-2024-55591 and CVE-2025-24472 in internet-facing devices, then use double extortion through data exfiltration and data encryption, while providing tailored detection guidance, IOCs, and mitigation recommendations aligned to Cross-Sector Cybersecurity Performance Goals (CPGs).
Show sources
- CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors — www.cisa.gov — 10.08.2026 15:00
- CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors — www.cisa.gov — 10.08.2026 15:00
- US and South Korea warn of Gunra ransomware targeting govt agencies — www.bleepingcomputer.com — 11.08.2026 12:47
- Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks — thehackernews.com — 11.08.2026 12:16
- Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure — www.infosecurity-magazine.com — 12.08.2026 16:15