Gunra ransomware CVE exploitation and double-extortion activity
Malware Activity
Summary
Hide ▲
Show ▼
The Gunra ransomware activity is actively exploiting CVE-2024-55591 and CVE-2025-24472 to reach internet-facing devices, putting victim systems and data at immediate risk. Once inside, the operators use double extortion to steal data and encrypt files. Victims are threatened with publication through a Tor-based portal if ransom is not paid within five to seven days. The activity spans critical infrastructure and multiple sectors worldwide.
Related Happenings
Gunra ransomware mitigation advisory (CISA/FBI/partners)
Advisory/Mitigation
H score38
First: 10.08.2026 15:00
Last: 10.08.2026 15:00
Sources 1
How related:
The advisory provides tailored detection guidance, indicators of compromise (IOCs), recommended actions if potential compromise is detected, and mitigation recommendations aligned to Cross-Sector Cybersecurity Performance Goals (CPGs).
About this happening:
CISA, FBI, DC3, NSA, USSS, and KNPA issued #StopRansomware: Gunra Ransomware to give organizations detection guidance, IOCs, and mitigation recommendations for G...
Gunra ransomware mitigation advisory (CISA/FBI/partners)
Advisory/MitigationHow related: The advisory provides tailored detection guidance, indicators of compromise (IOCs), recommended actions if potential compromise is detected, and mitigation recommendations aligned to Cross-Sector Cybersecurity Performance Goals (CPGs).
About this happening: CISA, FBI, DC3, NSA, USSS, and KNPA issued #StopRansomware: Gunra Ransomware to give organizations detection guidance, IOCs, and mitigation recommendations for G...
Luxury jewelry retailer hit by ransomware attack
Incident
H score45
First: 07.07.2026 16:27
Last: 07.07.2026 16:27
Sources 1
About this happening:
A luxury jewelry retailer suffered a help-desk social engineering intrusion in May 2025 that led to account takeover and the theft of at least 77 gigabytes of data...
Luxury jewelry retailer hit by ransomware attack
IncidentAbout this happening: A luxury jewelry retailer suffered a help-desk social engineering intrusion in May 2025 that led to account takeover and the theft of at least 77 gigabytes of data...
Silent Ransom Group shifts from Conti-linked ransomware participation to standalone data-theft extortion
Threat Actor Meta
H score21
First: 07.06.2026 17:09
Last: 07.06.2026 17:09
Sources 1
About this happening:
Silent Ransom Group (UNC3753) is a standalone data-theft extortion actor that has operated separately since 2022 after the Conti shutdown, using stolen data and le...
Silent Ransom Group shifts from Conti-linked ransomware participation to standalone data-theft extortion
Threat Actor MetaAbout this happening: Silent Ransom Group (UNC3753) is a standalone data-theft extortion actor that has operated separately since 2022 after the Conti shutdown, using stolen data and le...
Storm-1175 high-velocity exploit campaign
Campaign
H score59
First: 06.04.2026 19:56
Last: 06.04.2026 19:56
Sources 1
About this happening:
Storm-1175 is running a high-velocity exploit campaign that rapidly turns access into Medusa ransomware deployment, creating risk of data exfiltration and encrypte...
Storm-1175 high-velocity exploit campaign
CampaignAbout this happening: Storm-1175 is running a high-velocity exploit campaign that rapidly turns access into Medusa ransomware deployment, creating risk of data exfiltration and encrypte...
Aleksey Olegovich Volkov sentenced in Yanluowang ransomware case
Law Enforcement
H score35
First: 24.03.2026 15:06
Last: 24.03.2026 15:06
Sources 1
About this happening:
The Justice Department said Aleksey Olegovich Volkov was sentenced to 81 months in prison for serving as an initial access broker in Yanluowang ransomware atta...
Aleksey Olegovich Volkov sentenced in Yanluowang ransomware case
Law EnforcementAbout this happening: The Justice Department said Aleksey Olegovich Volkov was sentenced to 81 months in prison for serving as an initial access broker in Yanluowang ransomware atta...
Timeline
-
10.08.2026 15:00 2 articles · 9h ago
CISA and partners warn on Gunra ransomware exploiting CVE-2024-55591 and CVE-2025-24472
Initial DisclosureCISA, FBI, DC3, NSA, USSS, and KNPA released a joint Cybersecurity Advisory on Gunra ransomware, describing it as a ransomware-as-a-service variant used by affiliates to target critical infrastructure sectors and organizations worldwide, including healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. The advisory says Gunra actors gain initial access by exploiting CVE-2024-55591 and CVE-2025-24472 in internet-facing devices, then use double extortion with data exfiltration, data encryption, and Tor-based publication threats if the victim does not pay the ransom within five to seven days.
Show sources
- CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors — www.cisa.gov — 10.08.2026 15:00
- CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors — www.cisa.gov — 10.08.2026 15:00