1. Executive summary
CISA, FBI, NSA, DC3, USSS, and the Republic of Korea's KNPA published a joint #StopRansomware advisory on 10 August 2026 warning that Gunra ransomware-as-a-service (RaaS) affiliates are actively targeting critical infrastructure sectors worldwide, including financial services. Gunra actors gain initial access by exploiting CVE-2024-55591 and CVE-2025-24472 in internet-facing firewall devices, then deploy a double-extortion model combining data exfiltration with encryption, demanding ransom within a five-to-seven-day window via a Tor-based portal. Attribution to the "Gunra" actor name is unconfirmed — no MITRE ATT&CK profile exists for this group in the verified reference data. EMEA financial services organisations with internet-facing firewall appliances exposed to these CVEs are at direct and immediate risk.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | Gunra's double-extortion model involves data exfiltration from financial services entities, which constitutes a major ICT-related incident requiring authority notification if a client is compromised. | Clients must have pre-built reporting workflows ready to notify competent authorities within DORA timelines if Gunra compromise is detected, covering both encryption and data-theft dimensions. |
| DORA Art. 24: digital operational resilience testing — general requirements | Initial access is via known CVEs (CVE-2024-55591, CVE-2025-24472) in internet-facing devices — precisely the class of vulnerability that resilience testing should identify and remediate. | Clients should verify that their vulnerability scanning and penetration testing programmes specifically cover internet-facing firewall appliances against these CVEs. |
No NIS2 or UK NIS articles are specifically engaged beyond generic incident-response obligations that apply to any security event.
3. Technical analysis & attack chain
Confirmed attack chain (multi-source corroborated)
- Initial access — Gunra affiliates exploit CVE-2024-55591 or CVE-2025-24472 in internet-facing firewall devices. The Record (Recorded Future) independently corroborates that the gang breaches organisations "through vulnerabilities in popular brands of firewalls." The specific firewall vendors and product lines are not named in the available source material.
- Double-extortion deployment — Once access is achieved, Gunra actors exfiltrate data and deploy encryption. The ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026 (single-sourced; DataBreaches.net citing the CISA advisory).
- Ransom negotiation — Actors negotiate through a Tor-based portal and threaten to publish exfiltrated data to a dedicated leak site (DLS) if the victim does not pay within five to seven days.
Technical specifics from the advisory
- CVE-2024-55591 — Exploited in internet-facing devices for initial access. No CVSS score, severity, or CISA-KEV status is available in the verified reference data for this CVE.
- CVE-2025-24472 — Exploited in internet-facing devices for initial access. No CVSS score, severity, or CISA-KEV status is available in the verified reference data for this CVE.
- Ransom window: 5–7 days from notification before leak-site publication.
- Negotiation infrastructure: Tor-based portal.
- Leak infrastructure: Dedicated leak site (DLS).
What is NOT in the source material: The advisory text available does not provide specific IOCs, file hashes, ransom-note filenames, encryption extensions, C2 domains/IPs, persistence mechanisms, privilege-escalation techniques, lateral-movement tooling, or command-line artefacts. The CISA advisory is stated to contain IOCs and detection guidance, but these were not included in the fetched source content. This advisory should be updated if the full advisory PDF is obtained.
Attribution caveat: The actor designation "Gunra" has no MITRE ATT&CK profile in the verified reference data. Attribution is unconfirmed. The advisory is a joint product of CISA, FBI, DC3, NSA, USSS, and KNPA, which lends credibility to the threat description, but the actor identity and RaaS structure are single-sourced to the advisory itself.
4. Mitigation & containment
P1 — Within 24 hours
- Identify all internet-facing firewall appliances in your estate and determine whether they are affected by CVE-2024-55591 or CVE-2025-24472. Consult vendor advisories for specific affected versions and patches.
- If vulnerable devices are identified and patches are available, apply them immediately. If no patch is available, isolate the device from the internet or apply vendor-recommended workarounds.
- Review firewall logs for signs of exploitation dating back to at least January 2025 (when Gunra first appeared). Look for anomalous administrative access, unexpected configuration changes, or unexplained outbound connections.
P2 — Within 72 hours
- Ensure network segmentation is in place such that a compromised firewall cannot be used for lateral movement into internal financial systems. Verify segmentation controls between DMZ and internal zones.
- Verify that backup systems are immutable, stored in a physically separate and segmented location, and tested offline. Confirm backup coverage for all critical financial data systems.
- Hunt for Gunra indicators: search for outbound Tor connections from firewall management segments and DMZ hosts. Block Tor exit nodes at the perimeter where feasible.
P3 — Within 7 days
- Update EDR and SIEM detection rules to alert on suspicious activity originating from firewall management interfaces.
- Review and tighten access controls on all internet-facing device management interfaces — enforce MFA, restrict management to VPN/management networks, and disable unused administrative accounts.
- Validate that incident response playbooks include a double-extortion scenario covering both encryption containment and data-exfiltration detection/notification workflows.
5. Indicators of compromise
No indicators of compromise available in the source material. The CISA advisory is stated to contain IOCs, but they were not included in the fetched source content. Clients should retrieve the full advisory directly from CISA at https://www.cisa.gov/news-events/news/cisa-fbi-and-partners-warn-organizations-gunra-ransomware-actors-targeting-multiple-critical and ingest any associated IOC files.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Exploitation of CVE-2024-55591 or CVE-2025-24472 on internet-facing firewall devices | Firewall logs, IDS/IPS alerts, firewall management logs | High — multi-source corroborated |
| Outbound Tor connections from compromised firewall or DMZ hosts | Network firewall logs, netflow, proxy logs | Medium — Tor-based negotiation portal is confirmed; specific connection patterns are inferred |
| Data exfiltration activity preceding or concurrent with encryption | DLP alerts, network egress monitoring, cloud storage access logs | Medium — double-extortion model confirmed; specific exfiltration methods not detailed in sources |
| Ransom demand with 5–7 day payment window communicated via Tor portal | Incident response, user reporting | High — confirmed in advisory |
6. Detection
Insufficient indicators to author detection rules. The source material does not contain file hashes, distinctive strings, command-line artefacts, mutex names, scheduled-task names, registry keys, ransom-note text, or other threat artefacts required to build functional YARA or Sigma rules. Clients should obtain the full CISA advisory and any accompanying IOC files for detection content.
7. Sources
- CISA — "CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors" — https://www.cisa.gov/news-events/news/cisa-fbi-and-partners-warn-organizations-gunra-ransomware-actors-targeting-multiple-critical — 2026-08-10
- DataBreaches.net — "CISA Advisory: #StopRansomware: Gunra Ransomware" — https://databreaches.net/2026/08/10/cisa-advisory-stopransomware-gunra-ransomware/ — 2026-08-10
- The Record (Recorded Future) — "FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure" — https://therecord.media/ransomware-south-korea-fbi-gunra — 2026-08-10
8. Adverse Trace position
Gunra represents an active and immediate threat to EMEA financial services organisations with internet-facing firewall appliances exposed to CVE-2024-55591 and CVE-2025-24472. The double-extortion model and short ransom window create both operational disruption and regulatory disclosure obligations. Attribution to "Gunra" is unconfirmed (no MITRE ATT&CK profile), and the technical detail available in the fetched sources is limited — the full CISA advisory is stated to contain IOCs and detection guidance that were not available at time of writing. We assess the severity as high for organisations with vulnerable internet-facing firewalls and moderate for organisations with fully patched or non-exposed appliances. Adverse Trace will update this advisory upon obtaining the full CISA advisory content with IOCs and detection artefacts. Clients should immediately enumerate exposed firewall assets and patch against the named CVEs.
Published via PulseTrace — Adverse Trace threat intelligence.