CISA, FBI, and South Korea Warn of Gunra Ransomware Hitting Critical Infrastructure
CISA, the FBI, and South Korean police warn that the Conti-derived Gunra ransomware group is exploiting Fortinet flaws and recruiting pentesters to hit government and critical infrastructure networks...
The FBI, the Cybersecurity and Infrastructure Security Agency, and three other U.S. agencies joined South Korea’s National Police Agency on Monday to warn government and critical infrastructure organizations worldwide about Gunra, a ransomware operation that has grown from a small Conti spinoff into a full ransomware-as-a-service platform in just over a year. The joint advisory, published under CISA’s #StopRansomware series and tracked as AA26-222A, lays out how Gunra breaks into networks, what it demands once inside, and why South Korean researchers now suspect North Korea’s Lazarus Group has been lending it a hand.
Table Of Content
A Conti Variant That Grew Into a Franchise
Gunra first appeared in April 2025 as a double-extortion ransomware variant built on Conti’s source code, which leaked online in February 2022, according to BleepingComputer’s reporting on the advisory. Like Conti, Gunra steals a copy of victim data before encrypting it, then threatens to publish the stolen files on a dedicated leak site unless victims pay through a Tor-based negotiation portal. The operation targeted Windows systems at first and added a Linux variant in mid-2025 to widen its reach into server environments.
In January 2026, Gunra converted itself into a formal ransomware-as-a-service business. The advisory says the group began offering affiliates “access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation” through listings on dark web forums. The FBI says Gunra has since operated under a new alias, Golden Community, and has been actively recruiting penetration testers and ethical hackers to work as initial access brokers, offering them a cut of ransom profits in exchange for a foothold on enterprise networks.
Fortinet Flaws Are the Preferred Way In
The advisory says Gunra’s most common entry point is a pair of authentication bypass vulnerabilities in Fortinet’s FortiOS and FortiProxy software, CVE-2024-55591 and CVE-2025-24472, both of which CISA had already warned about in earlier advisories. South Korea’s police agency also observed Gunra affiliates breaking in through exposed credentials and weak SSH access controls on internet-facing VPN gateways. Once affiliates are inside a network, some have tried a more direct pressure tactic: the FBI said it “observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments with limited success.” According to the advisory, Gunra typically opens negotiations at arbitrarily high demands, often in the tens of millions of dollars, and tells victims to begin talks within five to seven days through its Tor-based negotiation portal or the messaging app qTox, or risk having their data published.
The advisory covers incidents across the Americas, Europe, the Asia-Pacific, the Middle East, and Africa, spanning healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation and logistics, government services, utilities, academia, media, retail, and professional and nonprofit services.
A Possible Lazarus Group Link
The warning lands weeks after South Korean cybersecurity firm AhnLab, working with government agencies in Seoul, reported that tools and infrastructure associated with North Korea’s state-backed Lazarus Group had turned up in Gunra’s attacks on South Korean organizations, as The Record reported. Monday’s advisory itself does not attribute Gunra to North Korea, but the overlap helps explain why South Korea’s National Police Agency joined CISA, the FBI, the Department of Defense Cyber Crime Center, the NSA, and the U.S. Secret Service in issuing the warning together.
“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations,” Chris Butera, who leads cybersecurity at CISA in an acting capacity, said in a statement reported by CyberScoop.
The agencies are urging network defenders to prioritize patching known exploited vulnerabilities on internet-facing systems, including VPN gateways and RDP-exposed infrastructure, segment networks to limit lateral movement if an intruder gets in, and keep offline, immutable backups in a separate, segmented location so a ransom demand isn’t the only way to recover encrypted data.








No Comment! Be the first one.