US and South Korea warn of Gunra ransomware targeting govt agencies
by Sergiu Gatlan · BleepingComputerU.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks.
In a Monday joint advisory, they said the ransomware group uses a malware variant based on the Conti ransomware source code leaked in February 2022, in attacks targeting a wide range of industry sectors, from healthcare and public health to financial and government services.
"Gunra first emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti1 ransomware source code," the authoring agencies said.
"The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments with limited success."
The ransomware gang has been observed attacking Fortinet firewalls to gain a foothold on their targets' networks using exploits targeting two critical authentication vulnerabilities (CVE-2024-55591 and CVE-2025-24472) in FortiOS and FortiProxy software.
Gunra also exploits credential-exposure and Secure Shell (SSH) access control security flaws in internet-facing VPN gateways to gain remote access to victims' systems. Additionally, while their attacks first focused on Windows environments, the ransomware actors moved to cross-platform campaigns after introducing a Linux variant in mid-2025.
Since January 2026, Gunra has also launched a dedicated ransomware-as-a-service (RaaS) platform and begun recruiting initial access brokers to expand operations.
"As of January 2026, Gunra launched a formal RaaS affiliate program on dark web forums, providing affiliates with access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation," the joint advisory says.
"The FBI observed the group adopting new branding aliases (notably operating under the name Golden Community) to support this expansion. Gunra has further commercialized its platform by actively recruiting penetration testers and ethical hackers to serve as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access."
The U.S. and South Korean agencies advised network defenders to patch known exploited vulnerabilities in internet-facing systems as soon as possible, segment their networks to restrict lateral movement, and make offline backups of their data.
This joint alert follows another advisory issued by South Korean cybersecurity firm AhnLab in collaboration with multiple South Korean government agencies that exposed links between the Gunra ransomware gang and Lazarus Group, a North Korean state-backed hacking group.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.