grid
Abstract circular gradient with concentric rings in blue, green, yellow, and red fading into black background.
5 min read

Gunra Ransomware Targets Governments and Critical Infrastructure

Gunra Ransomware
Published on
August 12, 2026

Six agencies across the United States and South Korea issued a joint alert on August 10. Their subject is a criminal operation that has grown from a small crew into a commercial platform. Gunra ransomware now targets government bodies and critical infrastructure worldwide, along with healthcare, financial services, manufacturing, and transport. The alert carries detection guidance, indicators of compromise, and a direct instruction to patch anything exposed to the internet.

The FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the US Secret Service, and South Korea's National Police Agency all signed it. That lineup reflects how seriously investigators now treat the group's expansion over the past year.

Where Gunra Ransomware Came From

The strain first surfaced in April 2025. Its developers did not build it from scratch. They took the Conti ransomware source code, leaked publicly in February 2022, and reworked it into the double-extortion tool now tracked as Gunra ransomware.

That inheritance matters. Conti ran one of the most productive extortion operations of its era before it collapsed, and its code carried mature encryption routines and lateral movement logic. Four years after the leak, criminal groups still mine it for working parts.

Early Gunra ransomware campaigns focused on Windows environments. The operators added a Linux variant in mid-2025 and moved to cross-platform attacks soon after. Linux servers and virtualisation hosts became viable targets, which widened the potential blast radius of a single intrusion.

How the Attackers Break In

Fortinet firewalls sit at the top of the list. Gunra ransomware affiliates exploit two critical authentication flaws in FortiOS and FortiProxy, tracked as CVE-2024-55591 and CVE-2025-24472, to reach networks from outside. Once they control a compromised appliance, they create their own accounts on it to hold that access.

VPN gateways offer a second route. The group hunts for exposed credentials and weak SSH access controls on internet-facing gateways, then pivots deeper into the environment. Systems with RDP open to the internet give them a third option.

None of this requires novel exploitation. Gunra ransomware campaigns rely on unpatched edge devices, and both Fortinet flaws have sat in public vulnerability catalogues for months.

From Small Crew to Franchise

January 2026 marked the turning point. The operators launched a formal ransomware-as-a-service affiliate programme on dark web forums, opening their toolset to anyone willing to split the proceeds.

Affiliates receive a management panel, a configurable builder, cross-platform locker payloads, and structured documentation. The Gunra ransomware package resembles a commercial software product more than a criminal toolkit. Investigators also recorded a new brand name tied to the expansion, Golden Community.

Recruitment went further than affiliates. The group has courted penetration testers and self-described ethical hackers to work as initial access brokers. In exchange for corporate network access, they offer a cut of the ransom payments. That structure splits the skill of breaking in from the business of extortion.

The Extortion Playbook

Attacks follow a familiar sequence. Affiliates steal data first, encrypt systems second, then push victims toward a customised Tor negotiation portal. Refusal leads to publication on a dedicated leak site.

One tactic stands out. Investigators observed Gunra ransomware operators emailing management staff at victim companies directly, going around IT and security teams to pressure executives into paying. Those attempts have met with limited success so far.

The approach still says something useful about how these groups think. They read internal hierarchies as a weak point, because the people who authorise payment are often not the people who understand the technical picture.

The North Korea Question

A separate report from late July alleged links between Gunra ransomware and Lazarus. A South Korean security firm produced it alongside several government agencies. Lazarus is the North Korean state-backed operation behind large cryptocurrency thefts, including the KelpDAO bridge exploit.

The joint advisory makes no such claim. Its authors describe a financially motivated criminal enterprise and leave it there. The state-actor connection remains an allegation, and readers should treat it as unconfirmed until the agencies behind this week's warning address it directly.

What Defenders Should Do Now

The recommended steps are short and specific. Patch known exploited vulnerabilities in anything internet-facing, with VPN gateways and RDP infrastructure first in line. Keep offline, immutable backups in a physically separate, segmented location so recovery never depends on paying.

Segment networks so one compromised device cannot open up the rest of the estate. Deny unnecessary SMB and RDP traffic between systems. Restrict administrative access to dedicated hardened workstations.

Teams that spot an intrusion before encryption begins have a narrow window to act. Identifying affected hosts and isolating them fast can keep an incident from turning into a full outage.

A Familiar Pattern With Wider Reach

The rise of Gunra ransomware follows a route security teams have watched before. A leaked codebase gives a new group a head start. Edge devices provide the way in. An affiliate programme then turns one working attack chain into a business that scales without the original operators lifting a finger.

Nothing in the advisory describes a technique defenders cannot counter. The gap sits in execution, because unpatched firewalls and flat internal networks remain common across organisations of every size.

Six agencies do not co-sign a warning for a marginal threat. Gunra ransomware has earned the attention, and the organisations most at risk are the ones still treating edge device patching as routine maintenance rather than urgent work.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.