None
CS
FBI puts govts on high alert over Gunra attacks targeting critical sectors worldwide
['Elijah Ntongai']
Tuko.co.ke
The FBI, alongside several US and South Korean security agencies, has issued a joint advisory warning organisations worldwide about Gunra, a rapidly expanding ransomware operation that has targeted critical infrastructure sectors and governments across at least ten industries.
How Gunra OperatesInvestigators first detected Gunra activity in April 2025.
Gunra employs double extortion tactics, stealing sensitive data before encrypting systems and threatening to publish or sell the information if victims refuse to pay.
Authorities traced initial access in many incidents to two authentication-bypass vulnerabilities, CVE-2024-55591 and CVE-2025-24472, affecting certain FortiOS and FortiProxy versions.
Tools Used and Sectors AffectedOnce inside a network, Gunra operators deploy tools including Impacket, Mimikatz, RClone, FileZilla, 7-Zip, AnyDesk, and Sliver to harvest credentials, move laterally, and exfiltrate data.