Gunra Ransomware Gang Exploits Firewall Vulnerabilities in Critical Infrastructure Attacks
The **Gunra** ransomware gang is actively breaching critical infrastructure organizations globally by exploiting vulnerabilities in popular firewall products. A joint advisory from the **FBI** and South Korea's government details the group's tactics, which include leveraging leaked **Conti** ransomware source code and demanding exorbitant ransoms.
The **Gunra** ransomware operation, first observed in April 2025, has been identified as a significant threat to critical infrastructure. A recent cybersecurity advisory from U.S. law enforcement agencies and South Koreaβs **National Policy Agency** highlights the group's use of leaked **Conti** ransomware source code, which became public in 2022.
**Chris Butera**, acting executive assistant director for cybersecurity at the **Cybersecurity and Infrastructure Security Agency (CISA)**, stated, "Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations."
### Exploiting Firewall Flaws
The advisory warns that **Gunra** actors are actively exploiting **CVE-2024-55591** and **CVE-2025-24472**, two vulnerabilities impacting widely used firewall products from **Fortinet**. These exploits grant them privileged access to victim networks, enabling data exfiltration and encryption before demanding ransom.
### Targeting Global Sectors
Evidence gathered by the **FBI** and South Korea's police agency reveals that **Gunra** is targeting organizations across the healthcare, financial services, and government sectors worldwide. Ransom demands often exceed $10 million, with victims typically given a tight payment window of five to seven days.
"The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments with limited success," the advisory noted.
### Evolving Tactics and Connections
Recent intelligence suggests potential links between **Gunra** and North Korea's **Lazarus Group**, with some tools and infrastructure appearing to be shared, particularly in attacks targeting South Korean organizations.
Initially emerging in April 2025, **Gunra** transitioned to a ransomware-as-a-service (RaaS) model by January, actively recruiting new members on cybercriminal forums. The group has also been observed using new aliases, such as "Golden Community," as it expands and commercializes its platform by enlisting initial access brokers.
### Linux Variant and a Fatal Flaw
While initially focusing on Windows devices, **Gunra** developed and deployed a Linux variant. However, researchers discovered a critical weakness in this Linux version as of March. This flaw allows defenders to "reconstruct the keys using file timestamps and recover files without paying the ransom," offering a potential avenue for recovery.
**Butera** affirmed that **CISA**, the **FBI**, and other agencies are actively sharing this advisory and related intelligence with government organizations and industry groups to counter **Gunra**'s ongoing attacks.
### Rising Ransomware Threat
This advisory comes amid increasing concerns from industry groups about the escalating number of ransomware incidents, particularly those targeting critical industrial organizations. Cybersecurity firm **Dragos** reported 1,140 ransomware incidents affecting industrial organizations globally in Q2 2026, marking a 12% increase from Q1. **Gunra** was attributed to at least four of these attacks in Q2, following eight attacks in Q1.