Gunra ransomware
Gunra Ransomware: FBI and South Korea Issue Joint Alert on Critical Infrastructure Threat

Gunra ransomware emerged from the leaked source code of the infamous Conti operation and has spent the last 16 months quietly building a ransomware-as-a-service empire that targets the world’s most critical infrastructure through unpatched firewalls — and on August 10, 2026, the FBI, CISA, NSA, U.S. Secret Service, and South Korea’s National Police Agency issued a joint advisory that signals this group has crossed from emerging threat to top-tier danger.

Key Takeaway

  • 🔒 The threat: Gunra ransomware is a ransomware-as-a-service operation built on leaked Conti source code, exploiting two Fortinet firewall vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to breach government, healthcare, financial services, and critical manufacturing organizations worldwide.
  • 📊 The scale: Dragos identified 1,140 ransomware incidents against industrial organizations in Q2 2026 alone — a 12% increase from Q1 — with Gunra responsible for at least 12 of those attacks across both quarters.
  • 💰 The demands: Ransom notes typically start at tens of millions of dollars, with victims given just five to seven days to begin negotiations through a Tor-based portal.
  • 🛡️ The defense gap: Gunra operates primarily between 10 PM and 6 AM local time, exploits default credentials and bypasses MFA, and has exfiltrated tens of terabytes of data through Microsoft OneDrive and SharePoint before encrypting a single file.
  • ⚡ Action: Prioritize patching Fortinet CVE-2024-55591 and CVE-2025-24472 immediately, implement immutable offline backups, and ensure overnight monitoring coverage does not drop below daytime levels.

The advisory itself is not a surprise to anyone tracking the ransomware landscape closely. What makes it significant is the convergence of three trends: Gunra ransomware has reached a level of operational maturity where six government agencies across two countries felt compelled to coordinate a public warning; the group’s use of legacy firewall vulnerabilities demonstrates that patching gaps remain the single most exploitable weakness in enterprise security; and the possible connection to North Korea’s Lazarus Group suggests state-level resources may now be flowing into criminal ransomware operations. For security professionals worldwide, the Gunra ransomware advisory is less a revelation and more a confirmation that the ransomware threat model has shifted again — and the defensive playbook needs to shift with it.

How Gunra Ransomware Built Its Operation

Gunra ransomware was first observed by the FBI in April 2025, when its ransomware binary and leak site appeared on the dark web. The group’s foundation is built on source code from the Conti ransomware, which was leaked in 2022 after the group’s internal chats were exposed. Conti’s code has since become a kind of open-source template for ransomware developers — multiple variants have spawned from it, and Gunra ransomware is the latest to reach sufficient operational scale to warrant a government advisory.

By January 2026, Gunra ransomware transitioned to a ransomware-as-a-service model, recruiting affiliates on cybercriminal forums and offering its platform to operators who bring their own initial access. The group also adopted new branding aliases, including the name “Golden Community,” as it expanded and commercialized. This rebranding pattern mirrors the evolution of groups like LockBit and ALPHV, which grew their affiliate programs while cycling through names to maintain operational security and evade law enforcement attention.

The group initially focused on Windows environments but expanded to a Linux variant, broadening its attack surface to include servers and cloud infrastructure running Linux. However, researchers discovered in March 2026 that the Linux variant contained a fatal flaw — its encryption keys could be reconstructed using file timestamps, allowing defenders to recover files without paying the ransom. This weakness may explain why Gunra ransomware continues to invest heavily in its Windows capabilities and data exfiltration tooling rather than relying on encryption alone.

The Fortinet Exploitation Gap

The technical core of the Gunra ransomware advisory is the group’s exploitation of two specific Fortinet vulnerabilities. CVE-2024-55591 and CVE-2025-24472 are authentication bypass vulnerabilities affecting specific FortiOS and FortiProxy versions. Both flaws allow unauthenticated attackers to gain privileged access to firewall management interfaces — essentially handing attackers the keys to the network perimeter without needing credentials.

What makes these vulnerabilities particularly dangerous is not their novelty — patches have been available for months, and CISA has previously warned about their exploitation by other ransomware groups. The problem is that patching rates for network edge devices remain stubbornly low. Firewalls and VPN appliances are often managed by separate teams, maintained during limited maintenance windows, and treated as “set and forget” infrastructure. Gunra ransomware exploits this exact gap.

Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, noted in response to the advisory that both vulnerabilities have been exploited by multiple ransomware groups, and that victims can remain compromised even after patching. “Patching fixes the entry point. It does nothing about an authentication backdoor already embedded in the MFA flow,” Krell said. “I’ve seen organizations close the vulnerability and declare themselves clean while the attacker’s persistence mechanism sat untouched in the auth stack.”

This observation cuts to the heart of why Gunra ransomware is so effective. The group’s post-exploitation techniques are designed to survive patching. In one observed case, Gunra ransomware actors exploited default credentials on an SSL-VPN appliance where account lockout controls were not enabled, then used the SSH tunnelling tool OpenSSH to establish persistent connections to an external server. In another case, the attackers modified authentication processing files on a corporate VDI authentication portal server, creating a continuous bypass of multi-factor authentication that would survive even after the original vulnerability was patched.

The Overnight Advantage

Perhaps the most operationally significant detail in the advisory is Gunra ransomware’s timing. The group primarily conducts malicious activities and internal infrastructure reconnaissance between 10:00 PM and 6:00 AM in the victim’s time zone — precisely when administrators are typically offline and detection coverage drops. This is not accidental. It is a deliberate exploitation of the staffing gap that most organizations have in their security operations centers.

Roman Sannikov, global research coordinator at iCOUNTER, emphasized this point: “If your detection coverage drops off overnight, that’s exactly the gap this group, now also operating under the alias Golden Community, is built to exploit.”

The group reinforces this stealth with aggressive log deletion. Gunra ransomware deletes system and network access logs and clears command history to hinder forensic analysis. The ransomware binary includes extensive filtering rules that focus only on files consistent with user data — avoiding non-critical files to streamline the collection of valuable, exfiltratable information. This surgical approach to data targeting maximizes the impact of the double-extortion model: victims face both encrypted systems and the threat of public data exposure.

The exfiltration itself is industrial-scale. The FBI observed Gunra ransomware actors using a malicious executable to extract data from Microsoft OneDrive and SharePoint, generating compressed archives of sensitive information and uploading them to the file-sharing service Mega. In at least one case, the actors successfully exfiltrated tens of terabytes of data before deploying encryption. This means that by the time an organization discovers the Gunra ransomware infection, the data theft has already been completed — the encryption is the announcement, not the beginning.

What the Numbers Tell Us — and What They Miss

The Dragos data — 1,140 ransomware incidents against industrial organizations in Q2 2026, a 12% increase from Q1 — provides the macro picture. Ransomware against critical infrastructure is not just continuing; it is accelerating. Gunra ransomware’s contribution to that total, at least 12 attacks across the first two quarters of 2026, may seem modest in absolute terms. But the group’s targeting pattern reveals a strategic focus on sectors where downtime costs are highest: healthcare, financial services, government, critical manufacturing, and transportation.

What the numbers miss is the human cost. Healthcare organizations targeted by Gunra ransomware face delayed treatments, rerouted ambulances, and compromised patient records. Financial services victims face regulatory penalties and loss of customer trust that can persist for years. The advisory’s emphasis on these sectors is not incidental — it reflects the FBI’s recognition that Gunra ransomware’s targeting pattern maximizes leverage by attacking organizations where the cost of not paying is measured in lives and livelihoods, not just dollars.

The ransom demands themselves reinforce this strategy. Gunra ransomware notes typically start negotiations at tens of millions of dollars, described in the advisory as “arbitrarily high,” but this is also a calculated psychological tactic. By opening at a figure that seems impossible, the group makes a subsequent “reduced” demand of one or two million appear reasonable by comparison — even though that reduced figure is still devastating for most organizations. The five-to-seven-day deadline adds pressure that prevents thorough incident response and encourages payment over investigation.

The Lazarus Connection and What It Means

Two weeks before the advisory, researchers reported that some tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with Gunra as it targeted South Korean organizations. This connection, if confirmed, represents a significant escalation in the ransomware threat landscape. State-sponsored hacking groups have historically operated separately from criminal ransomware operations, with different objectives and different operational security postures. If Lazarus is providing tools, infrastructure, or expertise to Gunra, the line between state-sponsored cyber espionage and criminal extortion is blurring in ways that make attribution, deterrence, and defense considerably more complex.

The South Korean connection also explains why the advisory is joint — the KNPA’s involvement signals that Gunra’s activities in South Korea have reached a level that warranted direct law enforcement collaboration with the United States. For organizations operating in the Asia-Pacific region, particularly those with infrastructure in South Korea, Japan, or the Philippines, this joint advisory is a direct signal that Gunra is active in their theater of operations. This connects to the broader pattern of rising cyber threats against government infrastructure that security teams across Southeast Asia are now tracking.

What Security Teams Must Do Now

The Gunra ransomware advisory’s mitigation guidance is straightforward, but its simplicity masks the organizational discipline required to implement it effectively. Three priorities stand out.

First, patch the Fortinet vulnerabilities. If your organization uses FortiOS or FortiProxy and has not yet applied the patches for CVE-2024-55591 and CVE-2025-24472, this is no longer a routine maintenance task — it is an emergency. The advisory confirms these specific CVEs are being actively exploited by Gunra ransomware, and CISA’s Known Exploited Vulnerabilities catalog already lists them. But patching alone is not sufficient. After patching, conduct a full review of authentication systems, MFA configurations, and VPN appliance settings to identify and remove any persistence mechanisms that Gunra ransomware may have implanted before the patch was applied.

Second, implement and test offline, immutable backups. The advisory specifically recommends backups stored in a physically separate, segmented location. This means backups that cannot be reached from the production network — not just a separate cloud bucket in the same account, not just a different folder on the same server. If Gunra can reach your backups, they will encrypt them too, and your recovery option disappears. Test restoration from these backups regularly; a backup that has never been restored is an untested assumption.

Third, address the overnight monitoring gap. If your security operations center reduces staffing or automated detection coverage outside business hours, Gunra will exploit that gap. Consider 24/7 monitoring, automated alert escalation for off-hours activity, and behavioral detection rules that flag anomalous activity between 10 PM and 6 AM regardless of whether a known threat indicator is present. This is also a good moment to review your incident response plan to ensure it accounts for after-hours discovery and escalation.

Network segmentation is the fourth pillar. The advisory recommends restricting lateral movement from initially compromised devices to other systems. If a VPN appliance is breached, the attacker should not be able to traverse freely into the corporate network, reach Active Directory, or access file shares containing sensitive data. Segmentation limits the blast radius of an initial compromise and buys time for detection and response. For organizations looking to strengthen their perimeter defenses against this class of threat, reviewing zero trust architecture principles provides a framework for reducing the impact of initial access breaches.

The Bigger Picture for Security Professionals

The Gunra advisory arrives at a moment when the ransomware threat landscape is undergoing structural change. Groups are operating with greater sophistication, adopting legitimate software tooling like OpenSSH and Mega for malicious purposes, and timing their attacks to exploit organizational gaps rather than technical vulnerabilities alone. The ransomware-as-a-service model means that the group developing the malware is not necessarily the group conducting the intrusion — affiliates bring initial access, and the platform provider takes a cut. This division of labor makes law enforcement takedowns more difficult because disrupting the platform does not disrupt the affiliates, who can simply move to another service.

For security professionals, the Gunra ransomware advisory is a reminder that the fundamentals matter more than the cutting edge. The vulnerabilities being exploited are not zero-days — they are months-old flaws with available patches. The initial access vector is not a sophisticated supply chain compromise — it is default credentials and unpatched authentication bypass. The persistence mechanism is not a novel rootkit — it is modified authentication files and SSH tunneling. Gunra ransomware succeeds not because it is technologically extraordinary, but because it executes reliably against the gaps that organizations consistently fail to close. The groups that succeed in defending against Gunra ransomware will be the ones that treat patching, backup testing, and 24/7 monitoring as non-negotiable operational discipline rather than periodic maintenance tasks. The conversation about building comprehensive cybersecurity defenses starts with exactly these fundamentals.

Frequently Asked Questions About Gunra Ransomware

What is Gunra ransomware?

Gunra ransomware is a ransomware-as-a-service operation that first appeared in April 2025, built on source code from the leaked Conti ransomware. It uses a double-extortion model, encrypting victim data while also threatening to publish stolen information on a dedicated leak site. The group operates under aliases including “Golden Community” and has been actively recruiting affiliates since January 2026.

Which vulnerabilities does Gunra exploit?

Gunra primarily exploits CVE-2024-55591 and CVE-2025-24472, two authentication bypass vulnerabilities affecting Fortinet FortiOS and FortiProxy firewall products. These vulnerabilities allow unauthenticated attackers to gain privileged access to firewall management interfaces. Patches are available for both flaws, but patching rates remain low across many organizations.

Which sectors does Gunra target?

According to the joint FBI, CISA, NSA, and South Korean police advisory, Gunra targets government organizations, healthcare, financial services, critical manufacturing, construction, transportation systems, utilities, academia, media and communications, and professional services. The group focuses on sectors where operational downtime carries the highest cost.

How much does Gunra demand in ransom?

Gunra ransom notes typically start negotiations at tens of millions of dollars, described in the advisory as “arbitrarily high.” Victims are given five to seven days to begin negotiations through a Tor-based portal. In some cases, the group has attempted to communicate directly with management staff at victim organizations via email.

How does Gunra maintain persistence after breaching a network?

Gunra uses multiple persistence techniques including SSH tunneling with OpenSSH to maintain connections to external servers, modifying authentication processing files on VDI portals to continuously bypass MFA, exploiting default credentials on SSL-VPN appliances, and deleting system logs and command history to hinder forensic detection. These mechanisms can survive patching of the original vulnerability.

Is Gunra connected to North Korea?

Researchers reported that some tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with Gunra during its targeting of South Korean organizations. The connection has not been formally confirmed by government agencies, but the joint involvement of South Korea’s National Police Agency in the advisory suggests the connection is being investigated seriously.

What should organizations do to defend against Gunra?

The advisory recommends four key actions: prioritize patching of known exploited vulnerabilities in internet-facing systems including VPN gateways, implement and test offline immutable backups in physically separate locations, segment networks to restrict lateral movement, and review the advisory’s indicators of compromise for evidence of potential Gunra activity. Organizations should also ensure 24/7 monitoring coverage since Gunra operates primarily between 10 PM and 6 AM local time.

Sources: CISA Joint Cybersecurity Advisory AA26-222A, The Record from Recorded Future News, Infosecurity Magazine, DC3 Advisory Bulletin

Editorial Transparency Note:This article was researched and drafted with AI assistance, then reviewed, verified, and approved by Edmon Agron. All sources have been cross-checked against original publications as of the date of publication.

Leave a Reply