US cybersecurity and intelligence agencies, alongside South Korea’s National Police Agency, have issued a joint advisory warning that the Gunra ransomware-as-a-service operation is actively targeting critical infrastructure sectors across the globe, including healthcare, financial services, and government facilities.
The advisory, published August 10 under the #StopRansomware banner, details how Gunra affiliates gain initial access by exploiting vulnerabilities in internet-facing Schneider Electric PowerLogic P5 devices (CVE-2024-5559) and Fortinet FortiOS and FortiProxy appliances (CVE-2025-24472). Once inside, the attackers deploy a double-extortion model combining data exfiltration and encryption, giving victims five to seven days to pay before stolen data appears on a leak site.
“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to US and international organizations,” said Chris Butera, CISA’s Acting Executive Assistant Director for Cybersecurity. The agencies involved include CISA, the FBI, the Department of Defense Cyber Crime Center, the NSA, the US Secret Service, and South Korea’s KNPA.
Since emerging in April 2025, Gunra has claimed 51 victims according to Ransomware.Live, with the majority concentrated in South Korea, Brazil, Spain, Thailand, and Hong Kong. The group leverages Impacket libraries for lateral movement via SMB and conducts credential dumping against compromised domain controllers. In some cases, actors have exfiltrated terabytes of data to MEGA file-sharing services.
One particularly alarming technique observed by South Korean investigators involves manipulating the network traffic control of SSL-VPN appliances to intercept user credentials and session cookies. In another incident, Gunra actors tampered with authentication processing files on corporate VDI portal servers, allowing successful authentication when a specific, attacker-designated one-time password value was entered, effectively bypassing multi-factor authentication.
The FBI noted that Gunra has adopted new branding aliases, including “Golden Community,” to expand operations, and has begun recruiting penetration testers and ethical hackers as initial access brokers, offering them a share of ransom profits. The Conti-derived operation launched a formal affiliate program on dark web forums in January 2026, providing affiliates with management panels, configurable builders, and cross-platform payloads.
Researchers at AhnLab have also identified potential connections between Gunra and a North Korean state-sponsored campaign that exploited vulnerabilities in financial security software to distribute malware. While the two groups appear to have separate objectives, shared techniques and infrastructure suggest possible limited collaboration, mirroring earlier observed partnerships between Lazarus sub-clusters and ransomware crews like Play and Medusa.
Agencies recommend organizations keep all software up to date, prioritize patching known exploited vulnerabilities in internet-facing systems, enforce network segmentation, ensure backups are immutable and stored in physically separate locations, and monitor for the indicators of compromise listed in the advisory. CISA Advisory AA26-222A | The Hacker News
discussion