#StopRansomware: Gunra Ransomware
2026-08-10T16:23:52Z•31662c950a816ecf77a75e838ad185a54222979d35884e581ed066f74ceb0742
CVE-2025-66376CISAChina-nexus activityGunraHMIICSIranian-affiliated actorsLAUNDRY BEAROTPLCRaaSRussian state-sponsored activitySCADAZimbra Collaboration Suitecompromised infrastructurecritical infrastructuredouble extortionincident responsenetwork segmentationnetworking devicesoffline backupsphishingpro-Russia hacktivistsransomwarevulnerability management
What happened
CISA advisories describe active ransomware, state-sponsored espionage, exploitation of vulnerable networking devices and internet-exposed industrial control systems, China-nexus covert infrastructure networks, pro-Russia hacktivism, and incident-response lessons. Key risks include Gunra ransomware double extortion, Russian exploitation of Zimbra CVE-2025-66376, attacks against exposed PLCs and critical infrastructure, and inadequate patching, monitoring, segmentation, and backup practices.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_alerts
- Record identifier
- 31662c950a816ecf77a75e838ad185a54222979d35884e581ed066f74ceb0742
- Enrichment time
- 2026-08-10T16:23:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.