U.S. and South Korean cybersecurity agencies have issued a joint warning about Gunra ransomware, an emerging ransomware-as-a-service (RaaS) operation targeting organizations across multiple sectors worldwide.
Gunra uses a double-extortion strategy, stealing sensitive data before encrypting systems and threatening to publish the stolen information if victims refuse to pay. The ransomware has targeted healthcare, financial services, government, utilities, manufacturing, transportation, academia, and other organizations.
How Gunra Gains Access
According to the advisory, Gunra affiliates have exploited known vulnerabilities in internet-facing Fortinet FortiOS and FortiProxy devices, including CVE-2024-55591 and CVE-2025-24472, to obtain initial access. Attackers have also abused exposed credentials and weak access controls on VPN infrastructure.
Once inside a network, attackers can move laterally, steal data, and deploy ransomware across compromised systems.
Recommended Security Measures
Organizations should:
Patch known exploited vulnerabilities on internet-facing systems.
Secure VPN and RDP infrastructure with MFA.
Segment networks to limit lateral movement.
Maintain tested, offline and immutable backups.
Monitor for suspicious administrative and remote-access activity.
Why It Matters
Gunra's shift toward a structured RaaS model means more cybercriminal affiliates can potentially conduct attacks using the group's infrastructure and tools. The broad range of victims demonstrates that critical infrastructure and enterprises remain attractive ransomware targets.
Conclusion
The latest warning highlights the need for organizations to prioritize vulnerability management, strengthen remote access security, and maintain resilient backups. Rapidly addressing vulnerabilities in internet-facing infrastructure can significantly reduce the risk of Gunra and similar ransomware attacks.