#StopRansomware: Gunra Ransomware

2026-08-10T16:23:52Z31662c950a816ecf77a75e838ad185a54222979d35884e581ed066f74ceb0742
CVE-2025-66376CISAChina-nexus activityGunraHMIICSIranian-affiliated actorsLAUNDRY BEAROTPLCRaaSRussian state-sponsored activitySCADAZimbra Collaboration Suitecompromised infrastructurecritical infrastructuredouble extortionincident responsenetwork segmentationnetworking devicesoffline backupsphishingpro-Russia hacktivistsransomwarevulnerability management

What happened

CISA advisories describe active ransomware, state-sponsored espionage, exploitation of vulnerable networking devices and internet-exposed industrial control systems, China-nexus covert infrastructure networks, pro-Russia hacktivism, and incident-response lessons. Key risks include Gunra ransomware double extortion, Russian exploitation of Zimbra CVE-2025-66376, attacks against exposed PLCs and critical infrastructure, and inadequate patching, monitoring, segmentation, and backup practices.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_alerts
Record identifier
31662c950a816ecf77a75e838ad185a54222979d35884e581ed066f74ceb0742
Enrichment time
2026-08-10T16:23:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.