Gunra RaaS Turns Edge Access Into Extortion

U.S. and South Korean agencies on Monday warned about Gunra, an emerging ransomware group that has grown into a ransomware-as-a-service operation and has been linked to victims across multiple sectors worldwide. The advisory says Gunra first surfaced in April 2025 and by early 2026 was recruiting outside hackers to help it break into networks. The group does not rely only on the ransomware itself. It buys or recruits initial access, then uses known vulnerabilities in internet-facing devices such as VPN gateways, firewalls, and RDP-exposed systems to get a foothold, after which it can push double extortion through a Tor-based negotiation site and leak site. That means the exposed edge device is often the real entry point, and cleanup has to account for the access path as well as the encryptor. For defenders, the important map point is where Gunra starts: organizations with reachable remote-access or perimeter gear are in the same exposure class even if the ransomware never lands through a phishing email or a payload download. In that setup, the gateway can become the doorway to broader network compromise and data theft pressure.

Part of the PlainSec briefing for 2026-08-11

Editions

Sources