Full Report
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]
Analysis Summary
# Incident Report: Gunra Ransomware Campaigns and RaaS Expansion
## Executive Summary
U.S. and South Korean agencies have issued a joint advisory regarding Gunra, a sophisticated ransomware group using a variant derived from leaked Conti source code. The group employs double-extortion tactics, targeting critical infrastructure through the exploitation of known vulnerabilities in Fortinet devices and VPN gateways. Recently, the group has evolved into a Ransomware-as-a-Service (RaaS) model and has been linked to North Korean state-sponsored activity (Lazarus Group).
## Incident Details
- **Discovery Date:** April 2025 (Initial emergence)
- **Incident Date:** April 2025 – Present
- **Affected Organization:** Multiple (Worldwide)
- **Sector:** Healthcare, Public Health, Financial Services, Government Services, and Critical Infrastructure
- **Geography:** Global (Specifically U.S. and South Korea)
## Timeline of Events
### Initial Access
- **Date/Time:** April 2025 (First observed emergence)
- **Vector:** Exploitation of Edge Devices
- **Details:** Attackers target internet-facing Fortinet firewalls and VPN gateways using specific authentication vulnerabilities and SSH access control flaws.
### Lateral Movement
- **Details:** The group utilizes network segmentation gaps to move through victim environments. In mid-2025, they expanded their capability to include Linux systems, facilitating movement across hybrid environments.
### Data Exfiltration/Impact
- **Details:** Gunra utilizes a "double-extortion" model, stealing sensitive data before encrypting systems to pressure victims into paying under the threat of data leaks.
### Detection & Response
- **January 2026:** Gunra officially launched a RaaS affiliate program and rebranded under the alias "Golden Community."
- **August 2026:** U.S. federal agencies and South Korea's National Police Agency issued a joint advisory following observations of direct ransom solicitations to management staff via email.
## Attack Methodology
- **Initial Access:** Exploitation of CVE-2024-55591 and CVE-2025-24472 (FortiOS/FortiProxy); credential exposure in VPN gateways.
- **Persistence:** Utilization of SSH access control security flaws.
- **Defense Evasion:** Use of Conti-based source code (modified) and rebranding under aliases like "Golden Community."
- **Discovery:** Active recruitment of Initial Access Brokers (IABs) and penetration testers for enterprise reconnaissance.
- **Lateral Movement:** Cross-platform lockers (Windows and Linux) and exploitation of internal network trust.
- **Exfiltration:** Double-extortion tactics (Data theft prior to encryption).
- **Impact:** Encryption of critical data and direct extortion of management staff.
## Impact Assessment
- **Financial:** Losses due to ransom demands; profit-sharing model established for RaaS affiliates.
- **Data Breach:** Compromise of healthcare, financial, and government records (Double-extortion).
- **Operational:** Disruption of critical infrastructure and government services.
- **Reputational:** Public disclosure of stolen data; direct harassment of executive leadership.
## Indicators of Compromise
- **Network Indicators:**
- Traffic associated with CVE-2024-55591 and CVE-2025-24472 exploitation.
- Unauthorized SSH connections to internet-facing VPN gateways.
- **File Indicators:**
- Gunra ransomware payloads (Windows/Linux variants).
- Configurable ransomware builders associated with "Golden Community."
- **Behavioral Indicators:**
- Direct email communication from threat actors to management staff.
- Large-scale data staging prior to encryption.
## Response Actions
- **Containment:** Agencies recommend immediate patching of Fortinet and VPN systems.
- **Eradication:** Identification and removal of unauthorized SSH keys and persistent Conti-based malware.
- **Recovery:** Implementation of offline, immutable backups to restore systems without paying ransoms.
## Lessons Learned
- **Patch Management:** Delayed patching of edge devices (firewalls/VPNs) remains the primary entry point.
- **Supply Chain of Cybercrime:** The transition to RaaS and the use of IABs allow ransomware groups to scale rapidly.
- **State-Sponsored Links:** The connection between Gunra and the Lazarus Group suggests that ransomware is increasingly being used as a tool for state-aligned objectives or revenue generation.
## Recommendations
- **Vulnerability Management:** Prioritize patching CVE-2024-55591 and CVE-2025-24472 in FortiOS/FortiProxy.
- **Network Hardening:** Implement strict network segmentation to limit lateral movement between IT and OT/Critical environments.
- **Access Control:** Secure VPN gateways with Multi-Factor Authentication (MFA) and audit SSH access logs.
- **Data Protection:** Maintain offline, encrypted backups and test restoration procedures regularly.
- **Executive Awareness:** Brief management staff on direct extortion tactics to prevent "social engineering" into paying ransoms.