rootpwn

Threat Intel

CISA, FBI Warn of Gunra Ransomware Surge Targeting Critical Infrastructure

CISA and the FBI alert that the Gunra ransomware gang is ramping up attacks across healthcare, energy, manufacturing, transportation, finance, and federal agencies. Using spear‑phishing, compromised vendor portals, and vulnerable remote‑desktop protocols, Gunra encrypts data and exfiltrates it before demanding ransom. The agencies urge immediate patching, MFA, offline backups, and incident reporting to mitigate the threat.

In a joint statement, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have warned that the Gunra ransomware gang is intensifying attacks across a broad swath of critical infrastructure.

What the attackers are doing

  • Targeting sectors such as healthcare, energy, manufacturing, transportation, finance, and federal agencies.
  • Deploying malware via spear‑phishing, compromised vendor portals, and vulnerable remote‑desktop protocols.
  • Encrypting files and exfiltrating data before demanding a ransom, a classic double‑extortion strategy.
  • Using the “Gunra” ransomware strain, which has been observed encrypting up to 1,200 files per infection.

Why it matters

Disruption in these industries can have ripple effects on public safety, national security, and the economy. The attackers have already crippled several hospitals and a state agency, forcing costly downtime and data loss.

Recommended defenses

  • Validate and patch all software, especially remote‑desktop and VPN endpoints.
  • Enforce multi‑factor authentication and least‑privilege access controls.
  • Maintain up‑to‑date, offline backups and test recovery procedures.
  • Monitor network traffic for anomalous data exfiltration and file‑encryption activity.
  • Educate staff on spear‑phishing and social‑engineering tactics.

“We urge all organizations in the affected sectors to act swiftly and share any indicators of compromise with CISA’s Cybersecurity Response Center,” the agencies said.

For more guidance, visit the CISA website or contact the FBI’s Cyber Division.

Gunra ransomware critical infrastructure CISA FBI double extortion incident response cybersecurity

← All news