Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

CISA, FBI and Partners Detail Gunra Ransomware Tactics

by Kristen Smith
August 11, 2026
in Cybersecurity, Department of War, DHS, News
NSA logo. CISA, the FBI, NSA and three other agencies released a joint advisory on Gunra.

Gunra actors encrypt data and threaten to publish stolen files within five to seven days.

  • The advisory carries seals from five U.S. agencies and South Korea’s national police
  • Gunra actors break in through two known vulnerabilities in internet-facing devices
  • Victims have been identified in five world regions and more than 10 sectors

Five U.S. agencies and a South Korean partner have published a joint advisory on Gunra, a ransomware operation that supplies its software to affiliates who carry out the attacks. The Cybersecurity and Infrastructure Security Agency, the FBI, the Department of War Cyber Crime Center, the National Security Agency, the U.S. Secret Service and the Korean National Police Agency released the document Monday under CISA’s #StopRansomware series.

Table of Contents

    • You might also like
    • CISA Seeks CIO to Lead Cybersecurity, IT & Communications Operations
    • White House Sends Navy Nominations of Hung Cao, William Toti, Richard Breckenridge to Senate
    • Troy Meink Details Air Force’s Continued Shift Toward Crewed-Uncrewed Force Design
  • How Do Gunra Actors Break In?
  • Which Organizations Has Gunra Hit?
  • What Do the Agencies Recommend?

You might also like

CISA Seeks CIO to Lead Cybersecurity, IT & Communications Operations

White House Sends Navy Nominations of Hung Cao, William Toti, Richard Breckenridge to Senate

Troy Meink Details Air Force’s Continued Shift Toward Crewed-Uncrewed Force Design

2026 Intel Summit. The Potomac Officers Club's Intel Summit will happen Sept. 24, with NSA Deputy Director Tim Kosiba as a keynote speaker.
NSA Deputy Director Tim Kosiba is a keynote speaker.

Cybersecurity in the age of agentic AI is a panel subject at the Potomac Officers Club’s 2026 Intel Summit on Sept. 24 at the Falls Church Marriott Fairview Park in Virginia. Tim Kosiba, deputy director of the National Security Agency, is among the keynote speakers. Register now.

Gunra surfaced as a ransomware variant in 2025 and moved to a ransomware-as-a-service model this year, NSA said Monday. Affiliates run a double-extortion scheme, locking up data and threatening to post stolen files to a leak site and sell them if the target refuses to pay.

How Do Gunra Actors Break In?

Two vulnerabilities give them their opening, CVE-2024-55591 and CVE-2025-24472, both in internet-facing devices.

Once inside, the actors work to stay hidden. NSA said they delete system and network access logs and wipe command history to frustrate detection and later analysis.

Data theft precedes encryption. The FBI observed operators taking business-critical documents, databases, personally identifiable information and internal email. Negotiations run through a Tor portal, where victims get five to seven days before the actors threaten to publish what they took.

Which Organizations Has Gunra Hit?

Victims have turned up in the Americas, Europe, the Middle East, Africa and the Asia-Pacific region, particularly those in the healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional and nonprofit services sectors.

What Do the Agencies Recommend?

Four measures head the list of mitigation recommendations from the agencies:

  • Keep operating systems, software and firmware current.
  • Give priority to patching known exploited vulnerabilities on anything facing the internet.
  • Hold backups that cannot be altered, kept in a separate and segmented location, and tested offline.
  • Segment networks so that a single compromised device cannot open a path to other systems.

The advisory also provides detection guidance, indicators of compromise and steps to take once a compromise is suspected.

“With our partners, CISA encourages organizations to urgently mitigate vulnerabilities identified in this advisory, implement recommended actions, and adopt security measures aligned to CPGs,” said Chris Butera, CISA’s acting executive assistant director for cybersecurity.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

RIMPAC 2026—5 Capability Demonstrations Defining the Next Era of Naval Warfighting

Next Post

Cameron Hamilton Sworn In as FEMA Administrator

Recommended For You

NASA-FEMA Partnership Offers Climate Adaptation Resources; Bill Nelson Quoted

by Kacey Roberts
June 12, 2022
NASA-FEMA Partnership Offers Climate Adaptation Resources; Bill Nelson Quoted

NASA and the Federal Emergency Management Agency have published an action guide meant to help communities make informed decisions on how to manage the risks of climate change. The “Building...

Read moreDetails

SPA Wins Contract to Support Force Design Division of ADF; Dr. William Vantine Quoted

by Sarah Sybert
July 9, 2020
Dr. William Vantine

Systems Planning and Analysis (SPA) Australia, a wholly owned subsidiary of SPA, Inc., has been awarded a contract to support the Force Design Division of the Australian Defense...

Read moreDetails

Accenture Acquires Homburg and Partner; Edwin van der Ouderaa Quoted

by William McCormick
May 18, 2021
Accenture Acquires Homburg and Partner; Edwin van der Ouderaa Quoted

Accenture announced on Tuesday that it has acquired Homburg & Partner, a strategic management consulting firm with deep specialization in commercial strategy, sales and pricing. Homburg & Partner’s...

Read moreDetails

Jim Garrettson, CEO of Executive Mosaic, Presents Jim McAleese, Principal and Owner of McAleese and Associates, His Third Wash100 Award

by William McCormick
April 10, 2019
Jim Garrettson, CEO of Executive Mosaic, Presents Jim McAleese, Principal and Owner of McAleese and Associates, His Third Wash100 Award

Jim Garrettson, founder and CEO of Executive Mosaic, presented Jim McAleese, principal and owner of McAleese and Associates, with his third Wash100 Award on Tuesday. Executive Mosaic recognizes...

Read moreDetails

Gen. John Raymond Confirms U.S. is Developing Directed-Energy-Systems For Space Defense; Gen. James Dickinson Quoted

by William McCormick
June 17, 2021
Gen. John Raymond Confirms U.S. is Developing Directed-Energy-Systems For Space Defense; Gen. James Dickinson Quoted

Gen. John Raymond, chief of Space Operations for the U.S. Space Force and 2021 Wash100 Award winner, recently acknowledged that the U.S. is currently developing directed-energy systems to...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Australia
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence Community
  • Legislation
  • M&A Activity
  • Middle East
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!