Government agencies and critical infrastructure organizations globally are being urged by U.S. federal agencies and South Korea's National Policy Agency to bolster their defenses against Gunra ransomware attacks. A joint advisory issued Monday, August 11, 2026, details that the Gunra ransomware group, which first appeared in April 2025, utilizes a variant of malware based on the Conti ransomware source code that was leaked in February 2022.
The ransomware group has been observed targeting a broad spectrum of industries, including healthcare, public health, financial services, and government entities. Initially, Gunra attacks focused on Windows environments, but by mid-2025, the actors introduced a Linux variant, expanding their campaigns to cross-platform operations. The FBI has noted instances where Gunra actors attempted to directly contact management staff at victim companies via email to solicit ransom payments, though with limited success.
To gain initial access to target networks, Gunra actors have exploited critical authentication vulnerabilities in Fortinet firewalls, specifically CVE-2024-55591 and CVE-2025-24472, affecting FortiOS and FortiProxy software. They also leverage credential exposure and Secure Shell (SSH) access control flaws in internet-facing VPN gateways to achieve remote access to victim systems.
Since January 2026, Gunra has significantly expanded its operations by launching a formal ransomware-as-a-service (RaaS) platform on dark web forums. This platform provides affiliates with a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured documentation. The group has also adopted new branding aliases, notably operating under the name "Golden Community," to support this expansion. Furthermore, Gunra is actively recruiting penetration testers and ethical hackers to serve as initial access brokers, offering them a share of the ransom profits in exchange for enterprise network access.
The U.S. and South Korean agencies recommend several defensive measures. These include promptly patching known exploited vulnerabilities in internet-facing systems, segmenting networks to restrict lateral movement, and maintaining offline backups of critical data.
This joint alert follows an earlier advisory from South Korean cybersecurity firm AhnLab, in collaboration with multiple South Korean government agencies. That previous advisory highlighted connections between the Gunra ransomware gang and the Lazarus Group, a hacking group widely believed to be state-sponsored by North Korea.






