U.S. federal agencies and South Korea’s National Police Agency issued a joint advisory warning government agencies and critical infrastructure operators worldwide to defend against Gunra ransomware attacks. The group, which first emerged in April 2025, runs malware built from the leaked Conti ransomware source code and has hit healthcare, financial services, government, and nonprofit sectors using a double-extortion model.

According to the advisory, the FBI observed Gunra actors emailing victim company management directly to pressure them into paying ransoms, though with limited success. The group has also rebranded some operations under the alias “Golden Community” as part of a broader expansion effort.

Exploited Vulnerabilities

Gunra has been observed breaching networks primarily through Fortinet products, exploiting two critical authentication vulnerabilities in FortiOS and FortiProxy: CVE-2024-55591 and CVE-2025-24472. The group also targets credential-exposure and SSH access control weaknesses in internet-facing VPN gateways to gain remote access.

Originally focused on Windows systems, Gunra expanded to cross-platform attacks after releasing a Linux variant in mid-2025.

RaaS Expansion

Since January 2026, Gunra has operated a formal ransomware-as-a-service affiliate program on dark web forums. The platform provides affiliates with a management panel, a configurable ransomware builder, cross-platform locker payloads, and affiliate documentation. The group has also been actively recruiting penetration testers and ethical hackers to act as initial access brokers, offering them a cut of ransom profits in exchange for enterprise network access.

The joint alert follows separate reporting from South Korean firm AhnLab, working with local government agencies, that identified links between Gunra and the North Korean state-backed Lazarus Group.

Recommendations

The advisory urges network defenders to prioritize patching known exploited vulnerabilities on internet-facing systems, segment networks to limit lateral movement, and maintain offline backups of critical data.