A joint advisory from CISA, FBI, National Security Agency (NSA), and partners warn that Gunra, an emerging ransomware-as-a-service operation, is targeting organizations worldwide. Gunra affiliates exploit vulnerable VPNs and firewalls, exposed credentials, and weak remote access controls to gain entry, steal sensitive data, and deploy ransomware, including CVE-2024-55591 and CVE-2025-24472. The group uses double extortion and has targeted cloud data, databases, NAS devices, and backup infrastructure.
Organizations should prioritize patching internet-facing VPN and remote desktop protocol (RDP) systems, strengthen access controls and network segmentation, and maintain routinely tested offline, immutable backups to reduce ransomware and recovery risks.