Cyberwarfare / Nation-State Attacks,
Fraud Management & Cybercrime,
Network Firewalls, Network Access Control
US and South Korea Tie Initial Access to Unpatched Firewalls and VPN Gateways

A recent cybersecurity alert issued jointly by U.S. and South Korean authorities has raised alarms regarding critical infrastructure sectors globally that continue to operate unpatched edge devices. These vulnerabilities have reportedly made them easy targets for a ransomware group, speculated to have links to North Korea. The U.S. agencies involved include the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the NSA, and the Secret Service, while their South Korean counterparts include the National Police Agency.
The ransomware group identified as Gunra specializes in ransomware-as-a-service operations and is persistently targeting exploitative vulnerabilities primarily found in VPN gateways and firewall appliances. The alert, released on a Monday, highlighted two specific vulnerabilities in Fortinet products. Despite patches having been issued in early 2025 to address these flaws, many organizations have not yet implemented them, leaving their systems at risk.
The joint intelligence report indicates that Gunra has amassed a wide variety of victims, ranging from healthcare and financial services to critical manufacturing and government sectors. In fact, the attackers have been reported to exfiltrate data that includes sensitive business-critical documents, databases containing personally identifiable information (PII), and internal email communications. This breadth of targets underscores the urgency for organizations to enhance their cybersecurity measures and conduct robust patch management practices.
To address these vulnerabilities, the advisory urges organizations to focus on patching known exploited vulnerabilities in internet-facing systems. This includes VPN gateways and any infrastructure exposed via remote desktop protocol. Additionally, the advisory stresses the importance of segmenting networks to limit hacker activity, as well as deploying immutable backups to safeguard against potential data loss.
Chris Butera, the acting executive assistant director for cybersecurity at CISA, commented that Gunra represents another worrying trend in ransomware attacks that are increasingly affecting both U.S. and international organizations. He emphasized the necessity for all organizations to promptly implement the recommended mitigations to reduce their vulnerability to similar cyber incidents.
Furthermore, Butera has encouraged organizations within critical infrastructure sectors to adopt version 2.0 of CISA’s cross-sector cybersecurity performance goals. These guidelines aim to establish common protective measures against the most frequently employed attack techniques by adversaries.
This alert follows earlier warnings issued by South Korean government and intelligence bodies. On July 30, authorities indicated they had been tracking both Gunra and another notorious hacking group known as Lazarus, which is believed to be state-sponsored and affiliated with North Korean cyber activities. Notably, the two groups were found to utilize similar malware and network infrastructures, alongside shared SSH key fingerprints. Both groups exploited the same vulnerabilities in security software deployed in South Korean financial services.
While it remains unclear whether Gunra affiliates might be linked to or functioning as independent hackers under the aegis of the North Korean government, South Korean cybersecurity firm AhnLab suggested these two clusters of threat activity might exhibit connections. The firm termed this campaign “Operation Double Barrel” to reflect the shared attack methodologies and overlapping technical frameworks observed between the groups.
Gunra’s ransomware operations surfaced in April 2025, initially deploying crypto-locking malware that appeared to derive from leaked Conti source code and was exclusively aimed at Windows systems. By mid-2025, the group diversified its capabilities to target Linux systems as well, illustrating an evolving threat landscape.
The group began its ransomware-as-a-service operation in January 2026, actively seeking to recruit affiliates who could aid in attacks. They introduced new branding, including monikers such as “Golden Community,” and incentivized penetration testers and ethical hackers to serve as initial access brokers. This recruiting strategy allowed Gunra to offer profit-sharing arrangements in exchange for access to enterprise networks.
Once attackers gain entry, they utilize various stealth techniques to evade detection. These include deleting system and access logs, wiping command histories, and conducting reconnaissance during late hours to obscure malicious activities from potential victims.
Unpatched Edge Gear Gets Popped
The FBI’s alert further detailed that Gunra has been able to secure remote access to victims’ systems by exploiting credential exposure and Secure Shell (SSH) access control vulnerabilities in exposed VPN gateways. Notably, two flaws affecting FortiOS, the operating system that governs FortiGate firewalls, and FortiProxy, the secure web gateway, remain critical vulnerabilities.
Fortinet has reported that successful exploitation of these vulnerabilities enabled hackers to establish super-admin privileges, allowing them to manipulate firewall configurations and create SSL VPN tunnels facilitating ongoing remote access.
Fortinet emphasized the critical nature of these vulnerabilities, urging customers to promptly apply the necessary patches. Despite these alerts being issued well in advance, many organizations are still vulnerable, as evidenced by the ongoing activities of ransomware groups like Gunra. The delay in patch implementation across diverse sectors illustrates a profound vulnerability that cybersecurity experts warn could lead to far-reaching consequences for both individual organizations and national infrastructure as a whole.
With persistence, the cyber threat landscape continues to evolve, illustrating that organizations must remain vigilant and proactive in safeguarding their networks against increasingly sophisticated cybercriminal tactics.

