TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/CISA, FBI, and South Korea Warn of Gunra Ransomware Hitting Critical Infrastructure
News

CISA, FBI, and South Korea Warn of Gunra Ransomware Hitting Critical Infrastructure

CISA, the FBI, and South Korean police warn that the Conti-derived Gunra ransomware group is exploiting Fortinet flaws and recruiting pentesters to hit government and critical infrastructure networks...

August 11, 2026 3 Min Read
38

The FBI, the Cybersecurity and Infrastructure Security Agency, and three other U.S. agencies joined South Korea’s National Police Agency on Monday to warn government and critical infrastructure organizations worldwide about Gunra, a ransomware operation that has grown from a small Conti spinoff into a full ransomware-as-a-service platform in just over a year. The joint advisory, published under CISA’s #StopRansomware series and tracked as AA26-222A, lays out how Gunra breaks into networks, what it demands once inside, and why South Korean researchers now suspect North Korea’s Lazarus Group has been lending it a hand.

Table Of Content

  • A Conti Variant That Grew Into a Franchise
  • Fortinet Flaws Are the Preferred Way In
  • A Possible Lazarus Group Link

A Conti Variant That Grew Into a Franchise

Gunra first appeared in April 2025 as a double-extortion ransomware variant built on Conti’s source code, which leaked online in February 2022, according to BleepingComputer’s reporting on the advisory. Like Conti, Gunra steals a copy of victim data before encrypting it, then threatens to publish the stolen files on a dedicated leak site unless victims pay through a Tor-based negotiation portal. The operation targeted Windows systems at first and added a Linux variant in mid-2025 to widen its reach into server environments.

In January 2026, Gunra converted itself into a formal ransomware-as-a-service business. The advisory says the group began offering affiliates “access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation” through listings on dark web forums. The FBI says Gunra has since operated under a new alias, Golden Community, and has been actively recruiting penetration testers and ethical hackers to work as initial access brokers, offering them a cut of ransom profits in exchange for a foothold on enterprise networks.

Fortinet Flaws Are the Preferred Way In

The advisory says Gunra’s most common entry point is a pair of authentication bypass vulnerabilities in Fortinet’s FortiOS and FortiProxy software, CVE-2024-55591 and CVE-2025-24472, both of which CISA had already warned about in earlier advisories. South Korea’s police agency also observed Gunra affiliates breaking in through exposed credentials and weak SSH access controls on internet-facing VPN gateways. Once affiliates are inside a network, some have tried a more direct pressure tactic: the FBI said it “observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments with limited success.” According to the advisory, Gunra typically opens negotiations at arbitrarily high demands, often in the tens of millions of dollars, and tells victims to begin talks within five to seven days through its Tor-based negotiation portal or the messaging app qTox, or risk having their data published.

The advisory covers incidents across the Americas, Europe, the Asia-Pacific, the Middle East, and Africa, spanning healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation and logistics, government services, utilities, academia, media, retail, and professional and nonprofit services.

A Possible Lazarus Group Link

The warning lands weeks after South Korean cybersecurity firm AhnLab, working with government agencies in Seoul, reported that tools and infrastructure associated with North Korea’s state-backed Lazarus Group had turned up in Gunra’s attacks on South Korean organizations, as The Record reported. Monday’s advisory itself does not attribute Gunra to North Korea, but the overlap helps explain why South Korea’s National Police Agency joined CISA, the FBI, the Department of Defense Cyber Crime Center, the NSA, and the U.S. Secret Service in issuing the warning together.

“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations,” Chris Butera, who leads cybersecurity at CISA in an acting capacity, said in a statement reported by CyberScoop.

The agencies are urging network defenders to prioritize patching known exploited vulnerabilities on internet-facing systems, including VPN gateways and RDP-exposed infrastructure, segment networks to limit lateral movement if an intruder gets in, and keep offline, immutable backups in a separate, segmented location so a ransom demand isn’t the only way to recover encrypted data.

Tags:

CISACritical InfrastructureFortinetnorth-koreaRansomware

Share

A stack of architectural blueprints on a drafting table, a visual metaphor for designing a GUI form before writing code
Previous Post

How to Build a Desktop Notes App in Python With PySide6 and Qt Designer

Mark Zuckerberg, Meta's CEO, in a 2025 official portrait
Next Post

Zuckerberg’s AI Manifesto Turns Philosophy Into a Regulatory Wish List

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026