/00 — boot sequence

Hello.

Article

Gunra Ransomware Targets Governments: US, South Korea Warn

August 11, 2026•5 min read
Gunra Ransomware CISA Advisory Fortinet Lazarus Group Ransomware

Introduction

US federal agencies and South Korea's National Policy Agency issued a joint advisory on August 11, 2026 warning government and critical infrastructure organizations worldwide about Gunra ransomware. The group runs a double-extortion ransomware variant derived from the leaked Conti source code, and the advisory is aimed at network defenders who still have exposed Fortinet firewalls, internet-facing VPN gateways, or weak SSH access control in their environments.

Gunra first appeared in April 2025, but the new alert matters now because the group has scaled up: a formal ransomware-as-a-service platform since January 2026, a Linux locker variant, and recruitment of initial access brokers. If you run FortiOS, FortiProxy, or any internet-facing VPN gateway, this advisory is worth reading before lunch.

What Happened

The joint advisory, published Monday under CISA advisory AA26-222A and echoed through a US-CERT bulletin, says Gunra has attacked a range of sectors including healthcare, public health, financial services, and government. The FBI observed the group emailing management staff directly at victim companies to solicit ransom payments, with limited success.

The agencies say Gunra is a sophisticated double-extortion variant derived from the leaked Conti1 ransomware source code, which has been circulating publicly since February 2022. Conti's codebase is battle-tested and has powered numerous ransomware families since the leak, and Gunra is the current iteration targeting government networks.

Attack Vector and Initial Access

The advisory details two main access paths. First, Gunra exploits two critical authentication bypass vulnerabilities in Fortinet products: CVE-2024-55591 and CVE-2025-24472, both in FortiOS and FortiProxy. These let an attacker gain a foothold on exposed firewall management interfaces without valid credentials.

Second, the group exploits credential-exposure and SSH access control flaws in internet-facing VPN gateways to reach victim systems remotely. Both paths point at the same hardening gap: perimeter devices with outdated firmware and permissive remote access policies.

For defenders, the message is that initial access is not exotic. These are known-exploited CVEs that have been patched for months, and the group is picking off organizations that never applied the fixes.

Infrastructure and Tooling

Gunra started as a Windows-only campaign and added a Linux variant in mid-2025, so victims on both platforms are in scope. The tooling includes a configurable ransomware builder, cross-platform locker payloads, and a management panel, all offered through a formal RaaS affiliate program launched on dark web forums in January 2026.

The group also rebranded under the alias Golden Community and has been actively recruiting penetration testers and ethical hackers to act as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access. That recruiting push is a signal that the gang wants volume, not just a few big hits.

Targeting and Victimology

Early Gunra activity focused on Windows environments across healthcare, public health, financial, and government services. The shift to a Linux locker and the RaaS expansion suggest the group is broadening from high-value targets to a wider pool of mid-size organizations, including those that run internet-facing Fortinet and VPN appliances.

Attribution and Threat Actor Profile

The US and South Korean advisory stops short of formal attribution, but context comes from South Korean security firm AhnLab. A July 30, 2026 report, dubbed Operation Double Barrel, exposed links between Gunra and the Lazarus Group, the North Korean state-backed hacking operation. AhnLab collaborated with multiple South Korean government agencies on that analysis.

If the Lazarus link holds, Gunra is not a typical profit-first criminal outfit. State-backed ransomware operations in the region have historically blended financial extortion with intelligence gathering and disruption, which changes the severity calculus for government and critical infrastructure victims.

Mitigation and Detection

The advisory lists three priorities for defenders. Patch known exploited vulnerabilities in internet-facing systems as soon as possible, especially the Fortinet CVEs referenced above. Segment your network to restrict lateral movement, so a compromised firewall or VPN does not become a highway to the whole estate. And keep offline backups of critical data, since double-extortion gangs encrypt and exfiltrate.

For detection, focus on the access paths the group actually uses:

  • Audit FortiOS and FortiProxy devices for CVE-2024-55591 and CVE-2025-24472 exposure, and check for unauthorized management sessions.
  • Review VPN gateway logs for anomalous authentication and credential-stuffing traffic.
  • Watch for unusual SSH access from unexpected source IPs, especially to Linux servers.
  • Deploy endpoint detection that flags Conti-family behavior, since Gunra shares its lineage.

Frequently Asked Questions

What is Gunra ransomware?

Gunra is a double-extortion ransomware variant derived from the leaked Conti1 source code. It encrypts victim files and steals data to pressure victims into paying, and has been active since April 2025.

Does Gunra affect Linux?

Yes. Gunra introduced a Linux variant in mid-2025 and now runs cross-platform campaigns alongside its original Windows locker.

Which vulnerabilities does Gunra exploit?

The group uses CVE-2024-55591 and CVE-2025-24472, two critical authentication bypasses in FortiOS and FortiProxy, plus credential-exposure and SSH access control flaws in internet-facing VPN gateways.

Is Gunra linked to North Korea?

AhnLab's July 2026 report, Operation Double Barrel, found links between Gunra and the Lazarus Group. The US and South Korean advisory does not make a formal attribution statement.

What should I do right now?

Patch internet-facing Fortinet and VPN devices, check for signs of prior access, segment your network, and verify offline backups. Full guidance is in CISA advisory AA26-222A.

Key Takeaways

  • Gunra ransomware, built on leaked Conti source code, is now the subject of a joint US and South Korea advisory targeting government and critical infrastructure.
  • Initial access relies on known Fortinet CVEs and VPN gateway misconfigurations, so patch hygiene is the primary defense.
  • The group added a Linux locker and a formal RaaS platform in 2025-2026, and is recruiting initial access brokers.
  • AhnLab research links Gunra to the Lazarus Group, adding a state-sponsored dimension.
  • Segment networks, patch perimeter devices, and keep verified offline backups.

Conclusion

Gunra is not a new name, but it is a newly scaled one. The RaaS expansion and the Fortinet exploit patterns make it a realistic threat for any organization running exposed perimeter devices. The joint advisory gives defenders a clear checklist: patch the known vulnerabilities, assume VPN access can be bought, and make sure the backups actually restore.


Sources: BleepingComputer, CISA advisory AA26-222A, US-CERT bulletin, AhnLab Operation Double Barrel

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links