US, South Korea Warn of Gunra Ransomware on Government Networks
TL;DR. US federal agencies and South Korea’s National Policy Agency issued a joint advisory about the Gunra ransomware targeting government and critical infrastructure globally. - Gunra is a sophisticated double-extortion ransomware variant derived from the leaked Conti source code. - The attackers exploit Fortinet vulnerabilities and use a ransomware-as-a-service model. - Gunra has expanded operations by recruiting initial access brokers and targeting cross-platform systems.
- US and South Korean authorities issued a joint advisory regarding Gunra ransomware targeting government and critical infrastructure.
- Gunra is a double-extortion ransomware variant based on leaked Conti source code, active since April 2025.
- The ransomware exploits Fortinet FortiOS/FortiProxy vulnerabilities and internet-facing VPN gateways for network access.
- Gunra operates a ransomware-as-a-service platform since January 2026, recruiting initial access brokers.
- Attacks have expanded from Windows to Linux environments, with links observed to the North Korean Lazarus Group.
Sources
- US and South Korea warn of Gunra ransomware targeting govt agencies — bleepingcomputer.com
- techcrunch.com — techcrunch.com