BTC$63,057+0.34% LTC$44.05+1.12% XMR$412.08+4.33%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Aug 10, 2026 · 2 min read · Original story

FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned on Monday.

In a cybersecurity advisory, U.S. law enforcement agencies and South Korea’s National Policy Agency spotlighted the ransomware operation that emerged in April 2025 and is built using source code from the Conti ransomware that was leaked in 2022.

“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations,” said Chris Butera, acting executive assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency (CISA).

The agencies warned that Gunra actors have been exploiting CVE-2024-55591 and CVE-2025-24472 — two vulnerabilities affecting popular firewall products from Fortinet that CISA previously warned about — to gain privileged access to organizations, allowing them to steal and encrypt data before extorting organizations.

Monday’s report included evidence gleaned from several incidents handled by the FBI and South Korea’s police agency. They found the group is targeting the healthcare, financial services and government sectors globally. In most cases, victims were given exorbitant ransom demands that were over $10 million dollars and told they had five to seven days to pay.

“The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments with limited success,” the advisory said.

Two weeks ago, researchers warned that some tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with Gunra as it targeted South Korean organizations.

The FBI said it first observed the ransomware and its leak site in April 2025. By January, Gunra moved to a ransomware-as-a-service model and the group was seen on cybercriminals forums actively recruiting new members.

In recent months, the FBI said it saw the group using new aliases, including the name “Golden Community,” as it has expanded and commercialized its platform by recruiting hackers to serve as initial access brokers.

The group initially focused on Windows devices but began using a Linux variant that it created. The advisory noted that as of March, researchers found a weakness in Gunra’s Linux variant that allows defenders to “reconstruct the keys using file timestamps and recover files without paying the ransom.”

Butera said CISA, the FBI and other agencies are sharing the advisory and other information with government organizations and industry groups to stop the group from continuing its attacks.

The advisory comes as industry groups warn that ransomware incidents continue to increase, particularly those targeting critical industrial organizations.

The cybersecurity firm Dragos said it identified 1,140 ransomware incidents affecting industrial organizations worldwide in the second quarter of 2026, a 12% increase compared to Q1. At least four of the attacks on industrial organizations last quarter were attributed to Gunra after the group was responsible for eight attacks in Q1.

References in this story

  1. #StopRansomware: Gunra Ransomware | CISA www.cisa.gov
  2. CISA warns of exploited Fortinet bugs as Microsoft issues its biggest Patch Tuesday in years therecord.media The federal government and multiple cybersecurity firms warned of a zero-day vulnerability in FortiGate firewalls that hackers are actively exploiting.
  3. 'Mora_001' ransomware gang exploiting Fortinet bug spotlighted by CISA in January therecord.media Two vulnerabilities impacting Fortinet products are being exploited by a new ransomware operation with ties to the LockBit ransomware group.
  4. North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn therecord.media Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidence of deepening entanglement between…
  5. Dark Web Informer (@DarkWebInformer) on X x.com ‼️Gunra Ransomware Launches New 2026 Affiliate Program on a Dark Web Forum
  6. Gunra Ransomware Group Unveils Efficient Linux Variant www.trendmicro.com This blog discusses how Gunra ransomware’s new Linux variant accelerates and customizes encryption, expanding the group’s reach with advanced cross-platform tactics.
  7. Gunra Ransomware's Linux Variant Has a Fatal Flaw: time()-Seeded rand() Makes Encrypted Files Recoverable Without Paying intel.breakglass.tech TL;DR: Gunra is a Conti-derived RaaS operation that expanded to Linux with a compact 84KB ELF binary targeting enterprise servers. Our analysis of the x86-64 variant reveals a catastrophic cryptographic weakness: the…
  8. Industrial Ransomware Analysis for Q2 2026 www.dragos.com Dive into Industrial Ransomware threats, trends, and effective strategies to protect your industrial operations from cyberattacks.
  9. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  10. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  11. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

← Back to all news