US federal agencies and South Korea’s National Policy Agency are warning government and critical infrastructure organizations worldwide to protect their networks against Gunra ransomware attacks.
A joint advisory said Gunra has targeted organizations in healthcare, finance, government and other sectors. The ransomware is based on leaked Conti source code and uses a double-extortion model, in which attackers steal data and then demand payment to prevent its release.
The ransomware gang has been observed targeting Fortinet firewalls to get access to victims' networks using two authentication flaws (CVE-2024-55591 and CVE-2025-24472) in FortiOS and FortiProxy software. Gunra also exploits credential-exposure and Secure Shell (SSH) access control security issues in internet-facing VPN gateways to gain remote access to victims' systems. The threat actor initially targeted Windows systems but has now expanded to Linux systems as well.
Since January 2026, Gunra has operated a ransomware-as-a-service service, allowing other criminals to use its tools in exchange for a share of ransom payments. The group has also recruited hackers who can help gain access to corporate networks.
The US and South Korean agencies urged organizations to patch known security flaws as soon as possible, separate important parts of their networks and keep offline backups of critical data.
Last month, South Korean security company AhnLab reported possible links between Gunra and the North Korean state-backed threat actor Lazarus, known for its brazen cryptocurrency thefts.