A coalition of U.S. and South Korean law enforcement and cybersecurity agencies issued a joint advisory warning about “Gunra,” a ransomware-as-a-service operation that has been used by affiliates to target critical infrastructure and organizations worldwide, including healthcare, financial services, government, and nonprofit sectors.
The advisory, published by CISA, the FBI, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and the Republic of Korea’s National Police Agency, says Gunra affiliates gain initial access by exploiting internet-facing devices through CVE-2024-5559 and CVE-2025-24472. Once inside, operators use a double-extortion playbook—exfiltrating data and encrypting systems—and conduct negotiations over a Tor-based portal, threatening to leak stolen data if a ransom is not paid within five to seven days.
“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations. To combat cyber threat activity, CISA continues to work with our government, industry and international partners to provide timely and actionable information that reduces the prevalence of damaging ransomware incidents,” said CISA Acting Executive Assistant Director for Cybersecurity, Chris Butera. “With our partners, CISA encourages organizations to urgently mitigate vulnerabilities identified in this advisory, implement recommended actions, and adopt security measures aligned to CPGs.”
Officials said the notice includes detection guidance, indicators of compromise, steps to take if a breach is suspected, and mitigation measures aligned to CISA’s Cross-Sector Cybersecurity Performance Goals. Recommended actions emphasize rapid patching and resilience planning to blunt the impact of disruptions and data exposure.
Key mitigation steps highlighted by the agencies:
– Keep operating systems, software, and firmware up to date.
– Prioritize patching Known Exploited Vulnerabilities in internet-facing systems.
– Ensure backups are immutable, stored in a physically separate, segmented location, and tested offline.
– Segment networks to prevent lateral movement from initially compromised devices.
The joint alert underscores the continued shift by ransomware groups to a service model that lowers the barrier to entry for affiliates and accelerates attacks across borders, and it urges organizations to review and implement the safeguards detailed in the advisory.




