A new and rapidly evolving cyber threat is commanding the attention of governments and critical infrastructure operators worldwide. In a joint advisory released Monday, U.S. federal agencies and South Korea’s National Policy Agency issued an urgent warning to secure systems against a sophisticated ransomware variant known as Gunra. This threat is not merely another strain of malware; it is a direct descendant of the notorious Conti ransomware, leveraging leaked source code to target a broad swath of sectors including healthcare, public health, financial services, and government agencies. The warning marks a significant escalation in the international effort to contain a ransomware operation that has already demonstrated technical sophistication, strategic adaptability, and a concerning connection to state-sponsored hacking groups.
Gunra Ransomware: A Direct Heir to the Conti Legacy
The Gunra ransomware first emerged in April 2025, but its origins trace back to one of the most consequential leaks in cybercrime history. According to the joint advisory, Gunra is a double-extortion ransomware variant derived from the Conti1 ransomware source code that was leaked in February 2022. The Conti group was once among the most prolific and dangerous ransomware operations in the world, responsible for attacks on healthcare systems, government networks, and critical infrastructure across multiple continents. When a Ukrainian researcher leaked the group’s internal communications and source code, it sent shockwaves through the cybercriminal underground, effectively arming a new generation of threat actors with battle-tested malware architecture.
What sets Gunra apart from other Conti spin-offs is the speed and intent with which it has evolved. Within months of its emergence, the group introduced a Linux variant, signaling a deliberate pivot toward cross-platform campaigns. This is not merely a technical upgrade; it represents a strategic expansion of the attack surface. Linux systems are widely deployed in cloud environments, web servers, and critical infrastructure control systems, making them high-value targets for any ransomware group seeking maximum impact. The joint advisory notes that Gunra’s initial focus was on Windows environments, but the introduction of the Linux variant in mid-2025 dramatically broadened the scope of its potential victims.
How Gunra Gains Access: Exploits, VPNs, and Credential Theft
Understanding how Gunra breaches its targets is essential for any organization seeking to defend against it. The advisory details a multi-pronged approach that combines software vulnerability exploitation with credential abuse. The ransomware group has been observed actively targeting Fortinet firewalls, exploiting two critical authentication vulnerabilities: CVE-2024-55591 and CVE-2025-24472. These flaws exist in FortiOS and FortiProxy software, widely used by enterprises and government agencies for network security and remote access. By compromising these devices, Gunra can establish a foothold on the network perimeter before moving laterally into more sensitive internal systems.
In addition to firewall exploits, Gunra has demonstrated a systematic approach to exploiting security flaws in internet-facing VPN gateways. Specifically, the group targets credential-exposure vulnerabilities and Secure Shell (SSH) access control weaknesses to gain remote access to victim systems. This is a particularly dangerous vector because it often requires no phishing or social engineering; the attackers simply scan for exposed services and exploit known vulnerabilities that have not been patched. The advisory emphasizes that the group’s ability to chain these exploits together reflects a high degree of operational maturity and technical capability.
What is the significance of the CVE-2024-55591 and CVE-2025-24472 vulnerabilities in the context of Gunra attacks? These are critical authentication bypass flaws in Fortinet products that allow an attacker to gain super-admin privileges without valid credentials. Once exploited, the attacker can disable security controls, deploy ransomware, and exfiltrate data with administrative-level access. Patching these vulnerabilities is the single most effective step an organization can take to prevent Gunra from establishing an initial foothold.
The Evolution into a Ransomware-as-a-Service Empire
Perhaps the most concerning development in Gunra’s trajectory is its formal transition to a ransomware-as-a-service (RaaS) model. As of January 2026, the group launched a dedicated RaaS affiliate program on dark web forums, complete with a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation. This is a watershed moment for the operation, as it transforms Gunra from a single actor into a platform that can be leveraged by multiple independent cybercriminals.
The joint advisory reveals that the FBI observed the group adopting new branding aliases to support this expansion, most notably operating under the name Golden Community. The decision to rebrand is a common tactic among ransomware groups seeking to evade law enforcement scrutiny while attracting new affiliates. By distancing themselves from the Gunra name in certain contexts, the operators can maintain operational flexibility and potentially avoid the kind of attribution that has led to sanctions and indictments against other ransomware groups.
What is the Gunra RaaS affiliate program and how does it operate? The program offers affiliates access to a centralized management panel where they can configure ransomware payloads, track infections, and manage ransom negotiations. Affiliates receive a configurable ransomware builder that can generate Windows and Linux lockers, along with documentation that outlines best practices for deployment and extortion. This lowers the technical barrier to entry, allowing even relatively inexperienced cybercriminals to conduct high-impact attacks in exchange for a share of the ransom proceeds.
The advisory also notes that Gunra has further commercialized its platform by actively recruiting penetration testers and ethical hackers to serve as initial access brokers. These individuals are offered a share of the ransom profits in exchange for providing enterprise network access. This is a particularly insidious development because it blurs the line between legitimate security research and criminal activity, potentially drawing in individuals who might otherwise never cross into outright cybercrime.
Direct Communication with Victims: A Novel Tactic
One of the more unusual aspects of Gunra’s operations is the group’s approach to ransom negotiations. The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments. This is a departure from the typical ransomware playbook, where negotiations are often conducted through chat portals on the dark web or through intermediaries. Direct email communication suggests a level of confidence and perhaps a desire to intimidate victims by demonstrating that the attackers have access to internal directories and email systems.
The advisory notes that these direct solicitations have met with limited success, suggesting that victims are either resistant to paying or that the group’s communication strategy has not yet been refined. However, the very fact that Gunra is willing to engage with senior management directly indicates a calculated effort to maximize psychological pressure. For security teams, this tactic underscores the importance of having robust incident response and crisis communication plans in place before an attack occurs.
The Lazarus Connection: State-Sponsored Links and Geopolitical Implications
The Gunra threat takes on an even more alarming dimension when viewed through the lens of geopolitical cyber conflict. This joint alert follows another advisory issued by South Korean cybersecurity firm AhnLab in collaboration with multiple South Korean government agencies that exposed links between the Gunra ransomware gang and the Lazarus Group, a North Korean state-backed hacking operation. Lazarus is one of the most infamous threat actors in the world, attributed to a string of high-profile attacks including the 2014 Sony Pictures hack, the 2016 Bangladesh Bank heist, and numerous cryptocurrency thefts and ransomware campaigns.
The connection to Lazarus Group transforms Gunra from a purely criminal enterprise into a potential instrument of state power. North Korean hacking groups are known for generating revenue through cybercrime to fund the regime’s weapons programs and other activities. If Gunra is indeed linked to Lazarus, then every ransom payment made to the group could have direct implications for international security. This linkage also raises questions about the degree of coordination between Gunra’s RaaS affiliates and North Korean state hackers. Is the RaaS platform a front for state-sponsored operations, or is it simply a revenue-generating venture that shares infrastructure with Lazarus? The advisory does not provide definitive answers, but the mere existence of the connection demands heightened vigilance from governments and private sector organizations alike.
For organizations operating in sectors deemed critical to national security, the Lazarus connection adds an extra layer of urgency to the Gunra threat. It is no longer just a matter of data loss and financial extortion; there is a real possibility that stolen data could be leveraged by a hostile state for espionage, influence operations, or economic warfare.
The Broader Industry Impact: Sectors at Risk
The Gunra ransomware attacks are not confined to any single sector. The joint advisory specifically identifies healthcare, public health, financial services, and government services as primary targets. Each of these sectors presents unique vulnerabilities that Gunra has proven capable of exploiting. Healthcare organizations, for example, often run legacy systems that are difficult to patch without disrupting patient care, making them attractive targets for ransomware actors who know that the cost of downtime can quickly exceed the ransom demand. Financial services firms, meanwhile, hold sensitive data that can be exfiltrated and used for secondary extortion, while government agencies face the dual threat of operational disruption and reputational damage if sensitive information is leaked.
The inclusion of critical infrastructure in the advisory’s warning is particularly significant. While the advisory does not name specific critical infrastructure sectors beyond healthcare and government, the technical capabilities demonstrated by Gunra suggest that energy, water, transportation, and communications networks could also be at risk. The group’s exploitation of Fortinet firewalls and VPN gateways indicates a focus on network perimeter devices that are commonly used across all critical infrastructure sectors.
Defensive Measures: What Organizations Must Do Now
In response to the escalating threat, the U.S. and South Korean agencies have issued a set of concrete defensive recommendations. The first and most urgent action is to patch known exploited vulnerabilities in internet-facing systems as soon as possible. This includes the Fortinet vulnerabilities CVE-2024-55591 and CVE-2025-24472, as well as any other CVEs that have been flagged as actively exploited by ransomware groups. Organizations that use Fortinet products should prioritize patching these flaws above nearly all other IT tasks, as the exploit chains are well-documented and likely to be used by affiliates of the Gunra RaaS platform.
The advisory also recommends that network defenders segment their networks to restrict lateral movement. This is a fundamental security practice that can limit the damage of any ransomware attack, regardless of the specific variant. By dividing the network into smaller, isolated segments with strict access controls, organizations can prevent an attacker who gains access to one system from easily moving to others. In the context of Gunra, which uses multiple entry points including VPNs and firewalls, network segmentation is an essential layer of defense.
Making offline backups of data is another critical recommendation. The “offline” qualifier is important; backups that are stored on the same network or on systems that are accessible from the network can be encrypted or deleted by ransomware. Immutable, air-gapped backups stored in a separate physical or cloud location ensure that an organization can recover its data without paying a ransom. The advisory emphasizes that regular testing of backup restoration procedures is equally important, as a backup that cannot be restored is no backup at all.
For organizations wondering how to defend against Gunra ransomware, the answer lies in a layered security approach that includes timely patch management, network segmentation, offline backups, and robust access controls. Additionally, monitoring for indicators of compromise related to the specific vulnerabilities and tactics used by Gunra can provide early warning of an impending attack. Security teams should review logs for unusual VPN connections, unauthorized access to Fortinet devices, and anomalous SSH activity.
Technical Deeper Dive: How Gunra Operates on Windows and Linux
Understanding the technical mechanics of Gunra’s operation can help security teams anticipate its behavior and build more effective defenses. The original Conti source code that Gunra is based on was written for Windows environments and featured a sophisticated multi-threaded encryption engine that could encrypt files quickly while avoiding system files that would render the machine unbootable. Gunra inherits these capabilities, using AES encryption for file content and RSA encryption for the key exchange, a standard approach that makes decryption without the attacker’s private key computationally infeasible.
The introduction of the Linux variant in mid-2025 represents a significant technical achievement. Linux ransomware is inherently more difficult to develop because of the diversity of distributions, file systems, and system configurations. That Gunra has managed to produce a working Linux locker suggests that the group has access to skilled developers who understand both operating systems at a deep level. The Linux variant is likely deployed against high-value targets such as web servers, database servers, and cloud infrastructure, which are disproportionately Linux-based.
The double-extortion aspect of Gunra adds another layer of damage. Before encrypting files, the attackers exfiltrate sensitive data and threaten to publish it if the ransom is not paid. This tactic, made famous by groups like Maze and REvil, has become standard across the ransomware ecosystem because it gives victims an additional incentive to pay. For organizations in regulated industries, the prospect of a data leak can be even more damaging than the ransomware infection itself, leading to regulatory fines, lawsuits, and loss of customer trust.
The RaaS Economy: How Gunra Is Reshaping Cybercrime
Gunra’s move to a RaaS model is part of a broader trend in cybercrime toward specialization and commercialization. By offering a management panel, a configurable builder, and structured documentation, Gunra is essentially acting as a software vendor to criminals. This lowers the barrier to entry and increases the overall volume of attacks. For defenders, this means that even organizations that are not specifically targeted by Gunra’s core operators could still be attacked by an affiliate who has purchased access to the platform.
The recruitment of penetration testers and ethical hackers as initial access brokers is a particularly innovative and troubling development. These individuals are uniquely positioned to identify and exploit vulnerabilities in enterprise networks. By offering them a share of ransom profits, Gunra creates a powerful financial incentive for skilled professionals to cross ethical lines. This blurs the distinction between legitimate security testing and criminal activity, potentially complicating legal and regulatory responses.
The use of the Golden Community alias for the RaaS platform suggests that Gunra is attempting to build a brand identity within the cybercriminal underground. A strong brand can attract more affiliates and foster a sense of community and loyalty among members. This is a mature strategy that has been used by successful RaaS operations like LockBit and Hive. The fact that Gunra is following this playbook so soon after its emergence indicates that its operators are experienced and well-connected within the cybercrime ecosystem.
Global Response and International Cooperation
The joint advisory from U.S. federal agencies and South Korea’s National Policy Agency is a testament to the international nature of the Gunra threat. The collaboration between CISA, the FBI, and South Korean authorities reflects a growing recognition that ransomware is a transnational problem that requires coordinated response. The advisory includes technical indicators of compromise, detection guidance, and recommended mitigation measures designed to be actionable by network defenders around the world.
For organizations in other countries, the advisory serves as an early warning that Gunra is likely to expand its operations geographically. The RaaS model inherently lacks geographical constraints; affiliates can target victims anywhere in the world. The advisory urges all critical infrastructure organizations to take immediate steps to secure their systems, regardless of their location or industry. The inclusion of specific technical guidance on the Fortinet vulnerabilities and SSH configuration weaknesses provides a clear starting point for defensive action.
What This Means for the Future of Ransomware
The emergence of Gunra as a major threat signals several important trends in the ransomware landscape. First, the Conti source code leak continues to have ripple effects years after the event. The codebase is being reused, modified, and improved by a new generation of threat actors, ensuring that the Conti legacy will persist for the foreseeable future. Second, the convergence of ransomware and state-sponsored hacking is becoming more pronounced, with groups like Lazarus potentially using criminal ransomware platforms as a cover for espionage and revenue generation. Third, the RaaS model is becoming more professionalized, with better tooling, documentation, and affiliate support than ever before.
For cybersecurity professionals, the Gunra threat demands a proactive and layered approach to defense. There is no single silver bullet that can protect against all possible variants and attack vectors. Instead, organizations must focus on the fundamentals: rigorous patch management, network segmentation, offline backups, access control, and user education. The advisory from U.S. and South Korean authorities provides a clear roadmap for these actions, but the responsibility for implementation lies with every organization that operates critical infrastructure or handles sensitive data.
The stakes are high. Gunra represents a convergence of technical sophistication, criminal entrepreneurship, and geopolitical intrigue that makes it one of the most serious ransomware threats to emerge in recent years. The response must be commensurate with the threat: coordinated, informed, and relentless.