U.S. and South Korean agencies on Monday warned about Gunra, an emerging ransomware group that has grown into a ransomware-as-a-service operation and has been linked to victims across multiple sectors worldwide. The advisory says Gunra first surfaced in April 2025 and by early 2026 was recruiting outside hackers to help it break into networks.
The group does not rely only on the ransomware itself. It buys or recruits initial access, then uses known vulnerabilities in internet-facing devices such as VPN gateways, firewalls, and RDP-exposed systems to get a foothold, after which it can push double extortion through a Tor-based negotiation site and leak site. That means the exposed edge device is often the real entry point, and cleanup has to account for the access path as well as the encryptor.
For defenders, the important map point is where Gunra starts: organizations with reachable remote-access or perimeter gear are in the same exposure class even if the ransomware never lands through a phishing email or a payload download. In that setup, the gateway can become the doorway to broader network compromise and data theft pressure.
CVSS 9.8 CRITICAL: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0… Known ransomware campaign use. EPSS 94% (100th percentile).
CISA federal remediation date Jan 21 · date passed
US and South Korea warn of Gunra ransomware targeting govt agencies
federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks.
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
and South Korean cyber agencies warn of Gunra, a rising ransomware gang using North Korean tools and recruiting ethical hackers to target critical infrastructure.