Cybercriminals are ramping up attacks on essential services with a dangerous extortion tool called Gunra ransomware. Federal safety officials warn that hackers actively lock files and demand payment. Taking simple defensive steps today can keep your operations running smoothly and protect your digital assets.
Threat Explanation
Gunra actors gain initial access by exploiting known vulnerabilities in internet-facing devices, specifically CVE-2024-55591 and CVE-2025-24472. They utilize a double-extortion model: after exfiltrating and encrypting your data, they negotiate via a Tor-based portal, giving victims a critical five-to-seven-day window to pay before they threaten to publish stolen data.
Who is at Risk?
| Targeted Sector |
|---|
| Healthcare systems and public health providers |
| Financial institutions and insurance companies |
| Government agencies and public service facilities |
| Utility providers and transportation systems |
| Schools, universities, and non-profit groups |
| Manufacturing and retail businesses |
Recommendations
Patch Vulnerable Systems
Prioritize patching known exploited vulnerabilities in internet-facing devices (specifically CVE-2024-55591 and CVE-2025-24472).
Secure Offline Backups
Ensure backups are immutable (cannot be altered), tested offline, and stored in a physically segmented location.
Segment Internal Networks
Implement network segmentation to prevent threat actors from using an initially compromised device to move laterally to other systems.
Enforce Multi-Factor Authentication
Require multi-factor authentication across all remote connections and secure administrative accounts with lockout rules.
Disable Unused Ports
Turn off unnecessary command-line utilities and inactive network ports to prevent privilege escalation.
Digital Hygiene Tip
Always keep your system software updated and maintain offline backups in a separate location. Regular software updates close security gaps before hackers can find them!