Skip to main content
Emerging ThreatsMalware & Ransomware

US, South Korea Warn of Gunra Ransomware Threat

City transit platform with disrupted digital screens and halted trains.

"Gunra first emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti1 ransomware source code," the authoring agencies said.

How Gunra has evolved since April 2025

The joint advisory from U.S. federal agencies and South Korea's National Policy Agency traces a clear timeline: Gunra appeared in April 2025, initially targeting Windows environments, then expanded to cross-platform operations after the group introduced a Linux variant in mid-2025. By January 2026 the gang had formalized a commercial ecosystem — launching a ransomware-as-a-service (RaaS) affiliate program on dark web forums that provides affiliates with a management panel, a configurable builder, and cross-platform locker payloads.

Exploited products and specific vulnerabilities: FortiOS and FortiProxy

Gunra actors have been observed attacking Fortinet firewalls to gain an initial foothold. The advisory names two critical authentication vulnerabilities used in those intrusions: CVE-2024-55591 and CVE-2025-24472 in FortiOS and FortiProxy software. The agencies explicitly warn network operators to patch known exploited vulnerabilities in internet-facing systems "as soon as possible."

Techniques observed: VPN gateway weaknesses, SSH, and social pressure

The group exploits credential-exposure and Secure Shell (SSH) access control flaws in internet-facing VPN gateways to obtain remote access to targets' systems. The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments, though the bulletin notes those solicitations had "limited success." Initially focused on Windows, Gunra’s development of a Linux variant signaled a push toward broader, multi-platform compromise.

Commercialization: RaaS, branding, and recruitment

Starting in January 2026, Gunra moved from a single gang to a platform operator. The advisory says the group adopted new branding aliases — "notably operating under the name Golden Community" — to support expansion, and it has commercialized access by recruiting initial access brokers. The RaaS offering gives affiliates a turnkey operation: a management panel, a configurable ransomware builder, cross-platform payloads, and structured documentation. The operators have also been reported to recruit penetration testers and ethical hackers, offering a share of ransom profits in exchange for enterprise network access.

What this means for network defenders, government agencies, and critical infrastructure operators

  • Network defenders: The advisory's immediate operational advice is concrete — patch internet-facing systems that include FortiOS/FortiProxy deployments for CVE-2024-55591 and CVE-2025-24472, segment networks to restrict lateral movement, and maintain offline backups of critical data.
  • Government agencies: The joint warning from U.S. federal agencies and South Korea’s National Policy Agency elevates Gunra to a transnational concern; agencies should prioritize patch management on internet-facing appliances and review remote access controls that expose SSH and VPN gateways.
  • Critical infrastructure operators: The combination of targeted firewall exploits, credential-exposure weaknesses, and an expanding RaaS ecosystem means operators face a higher risk of initial compromise and of multiple adversaries using the same tooling once affiliates obtain access.

Detection, telemetry, and the operational problem

The advisory underscores an operational gap: the page containing the advisory also included an industry statistic that "Security teams log 54% of successful attacks and alert on just 14%." Whether read as a caution or a call to test controls, that figure aligns with the agencies' direction to harden external-facing systems and to limit attackers' ability to move laterally once inside. The RaaS model and recruitment of initial access brokers increase the number of potential entry vectors, placing a premium on timely patching, robust segmentation, and reliable offline backups.

The facts the agencies laid out are straightforward and specific: named CVEs used against named products, the group's timeline from April 2025 emergence to a January 2026 RaaS launch, direct outreach attempts to corporate management, and a shift from Windows-only to cross-platform operations after mid-2025. Those items map to practical, immediate tasks for defenders and to a cautionary note about how commoditized access and affiliate programs multiply risk.

Link to original advisory and reporting: https://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/