Gunra Ransomware Surges, Hits 50+ Organizations Across Key Sectors

3 min readSources: National Law Review

Gunra ransomware has attacked over 50 organizations globally in a recent surge.

Why it matters: Legal and compliance teams must prepare for increased ransomware threats that pose data breach risks and legal reporting obligations under breach notification laws and contractual agreements.

  • Gunra ransomware-as-a-service (RaaS) has been active since 2025, based on leaked Conti code.
  • Recent attacks have hit 50+ organizations worldwide across healthcare, finance, manufacturing, transportation, and government.
  • The group exploits firewall and VPN vulnerabilities, including CVE-2024-55591 and CVE-2025-24472, to gain access.
  • Uses double-extortion: encrypting data and threatening release unless ransom paid; employs lateral movement using tools like Impacket’s psexec.py (a remote code execution tool).
  • Authorities like the U.S. NSA recommend patching, offline backups, and network segmentation for defense.

The Gunra ransomware group has escalated a global attack campaign, recently breaching more than 50 organizations across key sectors such as healthcare, finance, manufacturing, transportation, and government. Active since 2025 and operating as a ransomware-as-a-service (RaaS), Gunra leverages a leaked Conti ransomware codebase, enabling affiliates to deploy complex ransomware attacks with coordinated management tools and multi-platform payloads. Security researchers at ITPro report this significant surge.

Gunra’s hallmark is its double-extortion approach: after encrypting critical data, the group threatens to publicly release stolen information, increasing pressure on victims to pay. Initial access typically exploits known vulnerabilities in internet-facing firewalls and VPN appliances, notably CVE-2024-55591 and CVE-2025-24472, both of which remain unpatched in some environments.

Once inside, the group moves laterally within corporate networks using legitimate Windows tools and open-source utilities such as Impacket's psexec.py, which allows remote code execution. This tactic enables Gunra to spread ransomware efficiently across systems.

Additional tactics include accessing virtual desktop infrastructures (VDI), extracting system configuration data prior to encryption, and deleting logs to evade detection. The group also reportedly recruits initial access brokers, including ethical hackers, offering them profit shares from ransoms, as confirmed by Cybersecurity experts at CSO Online. This recruitment strategy helps Gunra rapidly expand its network of attackers.

For legal and compliance teams, this surge intensifies the risk of data breaches triggering breach notification laws and contractual liabilities. Authorities such as the U.S. National Security Agency (NSA) recommend key mitigations including prompt patching of known vulnerabilities, maintaining offline backups, and network segmentation to limit lateral movement. Implementing these defenses is critical as ransomware attacks grow in both frequency and sophistication.

By the numbers:

  • 50+ organizations attacked — recent Gunra ransomware campaign impact
  • 2025 — year Gunra ransomware service began operations
  • 2 known CVEs exploited — CVE-2024-55591 and CVE-2025-24472

Yes, but: While Gunra’s recruitment of ethical hackers aligns with the trend of initial access brokers, some claims rely on industry observations without formal confirmation from involved parties.

What's next: Organizations should watch for further advisories from cybersecurity agencies and prepare for potential ransom negotiations and regulatory investigations as the Gunra campaign unfolds.