US and South Korea warn of Gunra ransomware targeting govt agencies

A sophisticated ransomware gang known as Gunra has been making headlines in recent months due to its targeted attacks on government agencies and critical infrastructure organizations worldwide. In a joint advisory issued by US federal agencies and South Korea’s National Policy Agency, it was warned that Gunra is using a malware variant based on the Conti ransomware source code leaked in February 2022, with devastating consequences.

Gunra first emerged in April 2025 as a double-extortion ransomware variant derived from the leaked Conti source code. The FBI has observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments, although this tactic has had limited success so far. However, what’s concerning is that Gunra has been exploiting critical vulnerabilities in Fortinet firewalls and internet-facing VPN gateways to gain a foothold on its targets’ networks.

In a particularly worrying trend, Gunra has moved from targeting Windows environments exclusively to launching cross-platform campaigns after introducing a Linux variant in mid-2025. This shift makes it even more challenging for organizations to defend against these attacks. Moreover, since January 2026, Gunra has launched a dedicated ransomware-as-a-service (RaaS) platform and begun recruiting initial access brokers to expand its operations.

The RaaS affiliate program on dark web forums provides affiliates with access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation. This commercialization of the platform has enabled Gunra to adopt new branding aliases and actively recruit penetration testers and ethical hackers as initial access brokers, offering them a share of the ransom profits in exchange for enterprise network access.

The joint advisory issued by US and South Korean agencies comes after another warning from South Korean cybersecurity firm AhnLab that exposed links between the Gunra ransomware gang and Lazarus Group, a North Korean state-backed hacking group. The recommended course of action for network defenders is to patch known exploited vulnerabilities in internet-facing systems as soon as possible, segment their networks to restrict lateral movement, and make offline backups of their data.

For organizations vulnerable to such attacks, it’s crucial to remember that prevention is key. This means regularly updating software and plugins, enforcing strict access controls, and investing in robust cybersecurity measures such as threat detection tools and incident response plans. By staying vigilant and proactive, businesses can minimize the risk of falling victim to sophisticated ransomware gangs like Gunra.


Source: Bleeping Computer — 2026-08-11