FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned on Monday.
In a cybersecurity advisory, U.S. law enforcement agencies and South Korea’s National Policy Agency spotlighted the ransomware operation that emerged in April 2025 and is built using source code from the Conti ransomware that was leaked in 2022.
“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations,” said Chris Butera, acting executive assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency (CISA).
The agencies warned that Gunra actors have been exploiting CVE-2024-55591 and CVE-2025-24472 — two vulnerabilities affecting popular firewall products from Fortinet that CISA previously warned about — to gain privileged access to organizations, allowing them to steal and encrypt data before extorting organizations.
Monday’s report included evidence gleaned from several incidents handled by the FBI and South Korea’s police agency. They found the group is targeting the healthcare, financial services and government sectors globally. In most cases, victims were given exorbitant ransom demands that were over $10 million dollars and told they had five to seven days to pay.
“The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments with limited success,” the advisory said.
Two weeks ago, researchers warned that some tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with Gunra as it targeted South Korean organizations.
The FBI said it first observed the ransomware and its leak site in April 2025. By January, Gunra moved to a ransomware-as-a-service model and the group was seen on cybercriminals forums actively recruiting new members.
In recent months, the FBI said it saw the group using new aliases, including the name “Golden Community,” as it has expanded and commercialized its platform by recruiting hackers to serve as initial access brokers.
The group initially focused on Windows devices but began using a Linux variant that it created. The advisory noted that as of March, researchers found a weakness in Gunra’s Linux variant that allows defenders to “reconstruct the keys using file timestamps and recover files without paying the ransom.”
Butera said CISA, the FBI and other agencies are sharing the advisory and other information with government organizations and industry groups to stop the group from continuing its attacks.
The advisory comes as industry groups warn that ransomware incidents continue to increase, particularly those targeting critical industrial organizations.
The cybersecurity firm Dragos said it identified 1,140 ransomware incidents affecting industrial organizations worldwide in the second quarter of 2026, a 12% increase compared to Q1. At least four of the attacks on industrial organizations last quarter were attributed to Gunra after the group was responsible for eight attacks in Q1.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



