In a significant cybersecurity alert, South Korean and U.S. cybersecurity and intelligence agencies have issued warnings regarding the emergence of Gunra ransomware. This new wave of ransomware is reportedly targeting critical infrastructure sectors and organizations across various regions globally, highlighting the persistent threat posed by cybercriminals.
The sectors most affected by these ransomware attacks comprise healthcare and public health, financial services, government facilities, along with professional and nonprofit services. Chris Butera, who is the Acting Executive Assistant Director for Cybersecurity at the Cybersecurity and Infrastructure Security Agency (CISA), expressed deep concern over this emerging threat. He indicated that Gunra represents a continuation of the alarming trend of ransomware attacks that disrupt operations and inflict damage on both domestic and international organizations.
The methodology behind Gunra relies on exploiting specific vulnerabilities in widely used software systems. In particular, attacks leveraging Gunra have been found to exploit security flaws in internet-facing Schneider Electric PowerLogic P5 and Fortinet FortiOS and FortiProxy appliances. These vulnerabilities facilitate initial access for the ransomware operators, allowing them to deploy the Gunra ransomware as part of a double extortion strategy. This strategy not only encrypts data but also involves the exfiltration of sensitive information to maximize pressure on victims to comply with ransom demands.
Victimized organizations face a grim ultimatum—failure to pay the ransom within five to seven days results in their data being published on a data leak site, further amplifying the stakes involved. According to data tracked on Ransomware.Live, Gunra has victimized at least 51 organizations since its emergence in April 2025. Among these targets, a notable concentration is found in South Korea, along with victims in Brazil, Spain, Thailand, and Hong Kong. Interestingly, the geographical focus of the attacks skews heavily towards Australia, East Asia, and Europe, with minimal representation in Canada and the United States.
The operational tactics of the Gunra group reveal a sophisticated understanding of cybersecurity vulnerabilities. Rakesh Krishnan, a noted security researcher, highlighted that the group employs phishing as a primary attack vector. Once a target is compromised, they engage in negotiations through a WhatsApp-themed chat panel. The group’s capabilities extend to encrypting substantial data volumes—up to 9 TB—within short timeframes by utilizing advanced encryption methods such as Salsa20 and ChaCha20, demonstrating significant technical skill in the execution of their attacks.
Gunra operates a formal Ransomware as a Service (RaaS) model openly in dark web forums. Since January 2026, they have been actively recruiting affiliates by providing them with access to a comprehensive management panel, a configurable ransomware builder, cross-platform payment systems, and detailed documentation. This affiliate model not only extends their operational reach but also monetizes the ransomware’s deployment by sharing ransom profits with initial access brokers.
Moreover, recent reports by the FBI suggest that the Gunra group has begun adopting new branding aliases, including Golden Community, in an apparent strategy to broaden its operational scope. In a notable shift, they have also started recruiting penetration testers and ethical hackers, who assist in gaining initial access to targeted networks while receiving a share of the ransom payments.
The attack chains orchestrated by the Gunra group are intricate. They utilize Impacket libraries for lateral movement within networks, deploying various utilities to establish persistence and conduct credential dumping against compromised domain controllers. Their malfeasance is not limited to simple data encryption; they meticulously cover their tracks by deleting system and network access logs, obfuscating their activities, and conducting reconnaissance during off-peak hours to avoid detection.
Victimized organizations have reported severe damage due to extensive data exfiltration. Sensitive business information, including critical documents and network configurations, have been harvested by attackers. These breaches often culminate in the deployment of ransomware to encrypt valuable assets, encompassing vital database servers and network-attached storage systems.
One particularly alarming incident reported by South Korea’s National Police Agency showcases the group’s ability to exploit an SSL-VPN appliance’s network traffic control functionalities to intercept user credentials. This tactic facilitated session hijacking, allowing attackers to impersonate legitimate users and infiltrate internal networks. Concurrently, the attackers have demonstrated the ability to compromise multi-factor authentication (MFA) protocols, thereby making unauthorized access visibly seamless.
In light of this emerging threat landscape, the collaboration between various threat actors raises concerns. Analysis of recent cyber activities suggests that Gunra may share methodologies and infrastructure with state-sponsored actors, particularly from North Korea. This collaboration hints at a potential unity between criminal enterprises and state-backed initiatives, blurring the lines between cybercrime and geopolitical objectives.
To combat the significant threat posed by Gunra, cybersecurity experts advise organizations to implement stringent security measures. Essential practices include regular updates of operating systems and application software, timely patching of known vulnerabilities, maintaining robust network segmentation, and ensuring that backups are immutable and securely stored.
As the threat of Gunra ransomware continues to evolve, organizations across all sectors are urged to remain vigilant, adopting proactive measures to safeguard their assets against increasingly sophisticated cyber threats. The collaboration and tactics employed by ransomware groups such as Gunra underscore the critical need for comprehensive cybersecurity strategies in today’s interconnected digital landscape.
