A ransomware operation that first surfaced in 2025 has developed into an international extortion business targeting organizations across multiple critical sectors. US and South Korean authorities are now warning that Gunra ransomware affiliates are exploiting vulnerable internet-facing systems, stealing credentials and removing large volumes of sensitive information before encrypting victim networks.

 

 

The warning comes from a joint advisory published on August 10 by the FBI, CISA, the US Department of Defense Cyber Crime Center, the NSA, the US Secret Service and South Korea’s National Police Agency. Authorities say Gunra has affected organizations across the Americas, Europe, the Middle East, Africa and Asia-Pacific, with victims spanning healthcare, finance, manufacturing, transportation, government, utilities, media and other industries.

Gunra was first observed by the FBI in April 2025. By January 2026, the operation had evolved into a ransomware-as-a-service business advertised to other cybercriminals on underground forums. Affiliates receive infrastructure that includes a management panel, configurable ransomware builder, and payloads capable of targeting multiple operating systems. The FBI has also seen the operation use the name Golden Community while expanding its affiliate program.

One of Gunra’s main routes into corporate environments has been vulnerable firewalls and VPN appliances exposed to the internet. Investigators specifically observed exploitation involving CVE-2024-55591 and CVE-2025-24472, two authentication bypass vulnerabilities affecting certain versions of Fortinet FortiOS and FortiProxy. South Korean investigators separately documented Gunra exploiting credential exposure and SSH access-control weaknesses in internet-facing VPN gateways.

Getting through the perimeter is only the first stage of the attacks. Authorities have observed Gunra extracting password hashes from compromised domain controllers and stealing legitimate session information. In one investigated intrusion, the attackers altered authentication processing files so that a Gunra-selected one-time password could repeatedly bypass multi-factor authentication.

Those credentials and sessions were then used to move further through victim environments. The advisory describes attackers reaching internal virtual desktop infrastructure, Active Directory servers, and desktops assigned to IT personnel. Gunra has also used commonly available tools from the Impacket collection to move between systems over Windows network connections.

Data theft occurs before the ransomware begins encrypting systems. The FBI has observed Gunra collecting databases, internal emails, personally identifiable information, and business-critical documents. In documented cases, attackers also targeted information stored in Microsoft OneDrive and SharePoint and packaged stolen material into compressed archives. Authorities say the amount taken from individual victims has reached tens of terabytes.

The stolen information becomes part of Gunra’s double-extortion strategy. Victims face both encrypted systems and threats that their confidential data will be published or sold if they refuse to pay. Gunra directs victims to a Tor-based negotiation portal before moving discussions to the encrypted qTox messaging service, typically providing five to seven days for negotiations. The advisory says initial ransom demands have reached tens of millions of dollars.

Gunra initially concentrated on Windows environments but introduced a Linux variant during 2025 as its operations expanded. Investigators assess that its ransomware is derived from, or significantly influenced by, the source code of Conti ransomware that leaked publicly in 2022.

Authorities are urging organizations to patch known exploited vulnerabilities on internet-facing equipment, particularly VPN gateways and exposed remote-access infrastructure. The advisory also recommends separating networks to restrict movement after an initial compromise and maintaining tested, offline and immutable backups in physically separate environments.

The agencies have not attributed Gunra to a particular country. Their August 10 advisory instead documents the group’s observed intrusion methods, ransomware infrastructure and indicators that defenders can use to investigate potentially compromised systems.

Leave a Reply