Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world.
Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services.
"Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations," CISA Acting Executive Assistant Director for Cybersecurity, Chris Butera, said.
Attacks deploying the ransomware have leveraged security flaws in internet-facing Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS and FortiProxy (CVE-2025-24472) appliances to obtain initial access, and then deploy the Gunra ransomware as part of a double extortion model that combines data exfiltration and data encryption for maximum impact.
Victims who refuse to pay up within five to seven days have their data published on a data leak site. According to data published on Ransomware.Live, Gunra has listed a total of 51 victims since emerging in the threat landscape in April 2025, with most of them from South Korea, Brazil, Spain, Thailand, and Hong Kong.
What's notable about the threat actor is that the majority of the targets are located in Australia, East Asia, and Europe. Only three victims have been reported from Canada and the U.S. so far.
"The group uses phishing as a main attack vector to deliver malicious pieces to their targets and carry out negotiations on a WhatsApp-themed chat Panel," security researcher Rakesh Krishnan said in an analysis published last year. "The group is capable of encrypting huge files (9TB) in a limited timeframe by using advanced stream cipher encryption such as Salsa20 or ChaCha20."
The Conti-derived operation is said to have launched a formal RaaS affiliate program on dark web forums in January 2026, providing affiliates with access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation.
The group offers both Windows and Linux variants of its locker, although an analysis released by Breakglass Intelligence in March 2026 identified a "catastrophic cryptographic weakness" in the Linux builds that made it possible to recover the encryption key and regain access to the files.
Per the U.S. Federal Bureau of Investigation (FBI), Gunra has been observed adopting new branding aliases, such as Golden Community, to expand its operations, while simultaneously taking steps to monetize its platform by recruiting penetration testers and ethical hackers to serve as initial access brokers, who are offered a share of the ransom profits in exchange for enterprise network access.
Attack chains are known to leverage Impacket libraries "psexec.py" and "smbclient.py" for lateral movement using the Server Message Block (SMB) protocol. Another Impacket utility, "secretsdump.py," is used to conduct credential dumping against compromised domain controllers and extract password hashes of user accounts from the NT Directory Services (NTDS) file.
To cover up traces of malicious activity, the group is known to delete system/network access logs, clear command history, and primarily conduct malicious activities and internal infrastructure reconnaissance between 10 p.m. and 6 a.m. Data exfiltration from Microsoft OneDrive and SharePoint is accomplished by means of an executable named "main.exe."
In select cases, the threat actors have been observed creating compressed archives containing terabytes of data and exfiltrating them to the MEGA file-sharing service. Besides collecting business-critical documents, the group is said to have connected to the virtual desktop infrastructure (VDI) environments of IT personnel and harvested sensitive documents containing system and network configuration information.
"The Gunra actors then leveraged enterprise server credentials stolen from a system access control server to deploy ransomware to encrypt key assets, including database servers and network-attached storage (NAS) systems," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said.
In one case spotted by South Korea's National Police Agency (KNPA), the attackers have been spotted manipulating the network traffic control functionality of an SSL-VPN appliance to intercept credentials and session information transmitted by users authenticating to a corporate VDI authentication portal. These stolen session cookies were then used to conduct session hijacking and impersonate legitimate users to gain access to the internal network.
To bypass multi-factor authentication (MFA), Gunra is said to have tampered with the authentication processing files on the corporate VDI authentication portal server such that it enabled successful authentication when a specific, Gunra-designated one-time password (OTP) value was entered.
Some of the other detected behaviors are listed below -
- Gaining access to an administrator account for an SSL-VPN appliance by exploiting default credentials and then downloading OpenSSH from an attacker-controlled server to set up connections between compromised systems and maintain persistence within the victim environment.
- Relying on an unused account identified in the SSL-VPN administrative web console that had access to both the internet and internal corporate network, and modifying its configuration to sidestep the mandatory password change requirement and empty it for follow-on activities.
- Accessing a Hiware system access control server via SSH from a compromised virtual desktop and stealing a symmetric encryption key stored on the server so as to decrypt passwords for enterprise server accounts stored within the database and perform credential dumping of credentials associated with all enterprise servers.
- Deleting backup and archived data stored on backup infrastructure at both the primary data center and disaster recovery center before and after the ransomware deployment.
The disclosure assumes significance in the face of a recent advisory from South Korea about a cyber campaign orchestrated by an unspecified state-sponsored threat group from 2025 through the first half of 2026 by exploiting vulnerabilities in an unidentified financial security software to distribute malware after tricking victims into visiting malicious URLs through spear-phishing and watering hole techniques.
Interestingly, some of these incidents have also involved the exploitation of the same financial security software vulnerabilities to deploy Gunra ransomware and exfiltrate sensitive organizational information.
Some of the watering hole attacks, per ENKI, have also exploited a zero-day vulnerability in AnySign4PC, causing malware to be installed and executed on systems with the certificate signing software installed when accessing the web page containing the exploit code. Some of the payloads distributed as part of the whole campaign include Struggle (aka SIGNBT 3.0) and Brandoor (aka COPPERHEDGE), both of which are known to be used by the Lazarus Group.
"These commonalities suggest that although the state-sponsored threat group and the Gunra ransomware group appear to be separate threat actors with different ultimate objectives, they may have shared certain techniques, tools, and infrastructure or collaborated to a limited extent during the attacks," AhnLab said.
While the exact origins of Gunra are unclear, this kind of collaboration between a North Korean nation-state group and a ransomware actor is not unheard of. As far back as October 2024, Palo Alto Networks Unit42 said it observed the Lazarus sub-cluster Andariel partnering with the Play ransomware crew.
Andariel itself has a track record of deploying custom ransomware families like SHATTEREDGLASS, Maui, and H0lyGh0st in the past. At least since September 2025, the Lazarus Group and its related intrusion set Moonstone Sleet (aka Storm-1789) have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
To secure against Gunra ransomware, organizations are advised to keep all operating systems, software, and firmware up to date, prioritize patching known exploited vulnerabilities in internet-facing systems, enforce network segmentation, and ensure backups are immutable and stored in a physically separate location.




