U.S. and South Korean cyber authorities issued a joint warning that the Gunra ransomware-as-a-service operation is targeting government and critical infrastructure organizations worldwide, using a double-extortion model that steals data before encrypting systems and threatening publication on a Tor-based leak site. The group, which appears derived from leaked Conti source code and emerged in 2025 before expanding into a formal affiliate program in 2026, has hit sectors including healthcare, finance, government, manufacturing, transportation, utilities, academia, media, and retail across multiple regions. Authorities said Gunra and its affiliates recruit initial access brokers, including penetration testers and self-described ethical hackers, and often demand more than $10 million with payment deadlines of five to seven days.
The advisory says Gunra commonly gains privileged access by exploiting known vulnerabilities in internet-facing infrastructure, particularly Fortinet firewalls, as well as VPN and RDP-exposed systems, before moving laterally, stealing data, and deploying ransomware on Windows and Linux environments. Separate research on the Linux variant found a major cryptographic flaw: the malware generates ChaCha20 key material with rand() seeded by time(), potentially allowing defenders to recover .GNRA files without paying if timestamps are preserved. Officials urged organizations to rapidly patch exposed edge devices, segment networks, and maintain offline immutable backups, while researchers also noted operational-security mistakes by the group and reported possible overlap between Gunra activity and infrastructure or tradecraft previously associated with North Korean actors in attacks on South Korean targets.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
CISA, the FBI, South Korea's National Police Agency, and other partners issued a #StopRansomware advisory warning that Gunra targets government and critical infrastructure organizations, uses double extortion, and exploits known vulnerabilities in internet-facing devices including Fortinet firewalls and VPNs.
AhnLab published research noting overlap between Gunra activity and North Korean government-linked tradecraft, assessing that techniques, tools, and infrastructure may have been shared or collaboration may have occurred to a limited extent.
Four ELF Gunra samples for x86-64, i386, and two ARM architectures were uploaded to MalwareBazaar, showing broader Linux platform support.
In March 2026, researchers reported that Gunra's Linux variant used time()-seeded rand() to generate ChaCha20 key material, allowing defenders to reconstruct keys from file timestamps and potentially recover encrypted files without paying.
Earlier in 2026, Gunra's leak site claimed semiconductor firm Trio-Tech as a victim. In a March 2026 SEC filing, Trio-Tech acknowledged a material cybersecurity event that resulted in the leaking of company data.
Gunra's affiliate recruitment post reportedly appeared on the RAMP dark web forum, marking its move toward a ransomware-as-a-service model.
Five Gunra-related .onion domains were listed in ThreatFox, providing infrastructure visibility into the operation.
By January 2026, authorities said Gunra had transitioned into a formal affiliate-driven ransomware-as-a-service operation and began recruiting members and initial access brokers under aliases including Golden Community.
Gunra reportedly attacked INHA University in South Korea and exfiltrated 650 GB of data.
In October 2025, U.S. authorities warned that Gunra was exploiting FortiOS vulnerabilities CVE-2024-55591 and CVE-2025-24472 to bypass MFA, create a persistent super-admin account via scheduled tasks, steal data, and deploy ransomware. The notice urged organizations to patch exposed Fortinet firewalls and VPNs and harden remote-access systems.
By July 2025, Gunra had expanded beyond Windows and developed a Linux variant of its ransomware.
Researchers and the FBI said Gunra first emerged or was first observed in April 2025 as a Windows-focused ransomware operation, along with its leak site.
The Conti ransomware source code leak later became the basis for assessments that Gunra was built from or influenced by Conti code.
The reference reports that Gunra claimed to steal 40 terabytes of data from a hospital in Dubai, illustrating the group's double-extortion activity against the healthcare sector. The article says the stolen data included enterprise information such as documents, databases, personal data, and internal email.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 44 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
25 references tracked. Mallory keeps watching after this page renders.
fortra.com
Open sourcewaterisac.org
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcecve.org
Open sourcesdxcentral.com
Open sourcebroadcom.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.