Gunra ransomware mitigation advisory (CISA/FBI/partners)
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CISA, FBI, DC3, NSA, USSS, and KNPA issued #StopRansomware: Gunra Ransomware to give organizations detection guidance, IOCs, and mitigation recommendations for Gunra ransomware risk. The advisory targets critical infrastructure sectors worldwide, including healthcare, financial services, government services and facilities, and professional and nonprofit services. It links the threat to exploitation of CVE-2024-55591 and CVE-2025-24472 on internet-facing devices and warns of double extortion. Defenders are told to urgently mitigate vulnerabilities, prioritize patching known exploited vulnerabilities, and align controls to CPGs.
Related Happenings
Gunra ransomware CVE exploitation and double-extortion activity
Malware Activity
H score38
First: 10.08.2026 15:00
Last: 10.08.2026 15:00
Sources 1
How related:
Gunra actors gain initial access by exploiting common vulnerabilities and exposures (CVEs)
CVE-2024-55591
and
CVE-2025-24472
in internet-facing devices. With access, Gunra actors use a double-extortion model that employs both data exfiltration and data encryption
About this happening:
The Gunra ransomware activity is actively exploiting CVE-2024-55591 and CVE-2025-24472 to reach internet-facing devices, putting victim systems and data at immediate r...
Gunra ransomware CVE exploitation and double-extortion activity
Malware ActivityHow related: Gunra actors gain initial access by exploiting common vulnerabilities and exposures (CVEs) CVE-2024-55591 and CVE-2025-24472 in internet-facing devices. With access, Gunra actors use a double-extortion model that employs both data exfiltration and data encryption
About this happening: The Gunra ransomware activity is actively exploiting CVE-2024-55591 and CVE-2025-24472 to reach internet-facing devices, putting victim systems and data at immediate r...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionAbout this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...
CISA-led joint advisory on Russian router targeting
Public Sector Action
H score32
First: 14.07.2026 15:00
Last: 14.07.2026 15:00
Sources 1
About this happening:
CISA and partner agencies released a joint cybersecurity advisory warning that Russian state-sponsored actors are targeting vulnerable networking devices in crit...
CISA-led joint advisory on Russian router targeting
Public Sector ActionAbout this happening: CISA and partner agencies released a joint cybersecurity advisory warning that Russian state-sponsored actors are targeting vulnerable networking devices in crit...
OFAC sanctions First VPN Service and two individuals
Regulatory/Legal Action
H score27
First: 14.07.2026 11:02
Last: 14.07.2026 11:02
Sources 1
About this happening:
OFAC sanctioned First VPN Service (1VPNS), Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev for enabling ransomware attacks and helping malicious software...
OFAC sanctions First VPN Service and two individuals
Regulatory/Legal ActionAbout this happening: OFAC sanctioned First VPN Service (1VPNS), Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev for enabling ransomware attacks and helping malicious software...
FIRESTARTER malware on Cisco ASA and FTD devices
Malware Activity
H score33
First: 23.04.2026 15:00
Last: 23.04.2026 15:00
Sources 1
About this happening:
CISA has published analysis of FIRESTARTER, a malware strain that enables remote access and control on Cisco Firepower and Secure Firewall devices, raising the ris...
FIRESTARTER malware on Cisco ASA and FTD devices
Malware ActivityAbout this happening: CISA has published analysis of FIRESTARTER, a malware strain that enables remote access and control on Cisco Firepower and Secure Firewall devices, raising the ris...
Latest development: 24.04.2026 23:34
CISA, NCSC-UK, and Cisco detailed Firestarter persistence on Cisco Firepower and Secure Firewall devices running ASA or FTD software, attributing the backdoor to UAT-4356 and linking the activity to ArcaneDoor. The malware modifies CSP_MOUNT_LIST, stores a copy in /opt/cisco/platform/logs/var/log/svc_samcore.log, restores itself to /usr/bin/lina_cs, and relaunches after termination or reboot; Cisco recommends reimaging and upgrading to fixed releases, or using a cold restart only if reimaging is not possible.
Timeline
-
10.08.2026 15:00 2 articles · 9h ago
CISA, FBI, DC3, NSA, USSS, and KNPA warn on Gunra ransomware
Initial DisclosureCISA, FBI, DC3, NSA, USSS, and KNPA released a joint Cybersecurity Advisory, #StopRansomware: Gunra Ransomware, warning that Gunra ransomware affiliates target critical infrastructure sectors worldwide, including healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. The advisory says Gunra actors gain initial access by exploiting CVE-2024-55591 and CVE-2025-24472 in internet-facing devices, then use double extortion through data exfiltration and data encryption, while providing tailored detection guidance, IOCs, and mitigation recommendations aligned to Cross-Sector Cybersecurity Performance Goals (CPGs).
Show sources
- CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors — www.cisa.gov — 10.08.2026 15:00
- CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors — www.cisa.gov — 10.08.2026 15:00