Skip to main content
Emerging ThreatsMalware & Ransomware

US, South Korea Warn of Gunra Ransomware Gang's Global Reach

Modern office setting with idle computers, hinting at disruption or concern.

“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations,” said Chris Butera, acting assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency, setting the tone for a joint advisory issued by U.S. and South Korean authorities.

U.S. and South Korean agencies’ alert

Monday’s advisory was published by CISA together with the Department of Defense’s Cyber Crime Center, the FBI, the National Security Agency, the Secret Service and the Republic of Korea’s National Police Agency. The notice is part of the #StopRansomware series, a joint FBI–CISA effort aimed at network defenders, and warns that Gunra has evolved into a ransomware‑as‑a‑service (RaaS) operation with growing ambition and commercial reach.

Gunra’s tactics: recruitment, branding, and double‑extortion

According to the advisory, the FBI first observed Gunra in April of last year. The group established a data leak site on Tor to list victims and publish stolen data, and by January of this year had launched a formal RaaS affiliate program. The agencies reported that Gunra has adopted new branding aliases — notably operating under the name Golden Community — to support expansion.

Gunra is described as a double‑extortion group: attackers both encrypt systems and threaten public release of purloined data. The advisory also highlights a notable change in how the group seeks initial access: Gunra is actively recruiting penetration testers and ethical hackers to act as initial access brokers, offering a share of ransom profits in exchange for enterprise network access.

Sectors targeted and geographic scope

The alert lists a wide range of victim types targeted by Gunra: academia; financial services and insurance; government services and facilities; healthcare; manufacturing and construction; media; retail; transportation; and utilities. The agencies emphasize that the group's operations are global, with observed activity across Africa, the Americas, the Asia‑Pacific, Europe and the Middle East.

Connections to prior ransomware code and North Korean‑linked tools

The advisory says Gunra seeks initial access using known vulnerabilities in internet‑facing devices such as firewalls or virtual private networks, and that its code is based on or influenced by the Conti ransomware code leaked in 2022. A separate research note published in July by South Korean cybersecurity firm AhnLab observed overlap between Gunra and operations linked to North Korean government‑linked hackers, although the research did not explicitly name that actor.

AhnLab wrote: “These commonalities suggest that although the state‑sponsored threat group and the Gunra ransomware group appear to be separate threat actors with different ultimate objectives, they may have shared certain techniques, tools, and infrastructure or collaborated to a limited extent during the attacks.” The advisory also places this reported collaboration in context, noting that North Korean government–ransomware gang collaboration dates back to at least 2024.

What this means for network defenders, policymakers, and recruited testers

  • Network defenders and security teams: The advisory—issued under the #StopRansomware banner—signals a need to monitor for exploitation of known vulnerabilities in internet‑facing devices, to watch for Tor data‑leak postings, and to be alert to unusual access that could stem from profit‑motivated recruitment of outside testers.
  • Policymakers and law‑enforcement partners: U.S. and Republic of Korea agencies have coordinated this advisory across multiple federal organizations, reflecting a cross‑agency effort to share indicators and to publicize the group’s evolving business model and use of known leaked code.
  • Penetration testers and ethical hackers: The advisory specifically notes that Gunra is actively recruiting these groups as initial access brokers, offering a share of ransom profits in exchange for enterprise network access—an explicit commercialization of roles traditionally limited to legitimate security testing.

The advisory documents a clear trajectory: Gunra moved from initial FBI observation in April of last year to operating a Tor leak site and then to formalizing an affiliate RaaS offering by January, adopting new branding along the way. Whether that commercial expansion—paired with recruitment of outside testers and reported overlap with North Korean‑linked tools—will broaden Gunra’s victim set or change defenders’ operational priorities remains the practical challenge named by the agencies monitoring the group.

Read the original advisory on CyberScoop: https://cyberscoop.com/us-south-korea-gunra-ransomware-warning/