-
Gunra is now using the ransomware-as-a-service model, where affiliates use its tools for attacking more people.
-
The hackers attack internet-facing systems, such as virtual private networks, steal data and then encrypt networks.
-
U.S. and South Korean security agencies have advised for rapid patching, multi-factor authentication, network segmentation, and offline backups.

US law enforcement and security agencies, together with the South Korean police have identified Gunra ransomware as a risk to governments, critical infrastructures, and businesses.
The FBI, CISA, NSA, U.S. Secret Service, Defense Cyber Crime Center, and South Korea’s National Police Agency warned about this in a joint advisory published on August 10.
Gunra came to public notice in April 2025, and by early 2026, it had expanded into a a full blown ransomware-as-a-service operation. This approach allows other cybercriminals to use Gunra ransomware in exchange for sharing any proceeds made.
Victims of Gunra ransomware have been seen in the Americas, Europe, Middle East, Africa, and Asia-Pacific.
Sectors targeted by Gunra ransomware include health care, financial services, manufacturing, construction, transportation, utility, government, education, retail, and professional services.
Gunra Breaks in Through Exposed Systems
The joint advisory shows that Gunra often starts with systems that can be reached from the internet. Hackers are now exploiting vulnerabilities in specific firewall and VPN devices. These backdoors were cited by the FBI, namely CVE-2024-55591, which affects Fortinet products, and CVE-2025-24472.
So if you are using any version of FortiProxy and FortiOS, then you could be exploited by these attacks. It allows a hacker to obtain high-level privileges via special requests. It has a high 9.8 CVSS score, and is now in CISA’s list of known exploitations.
CVE-2025-24472 is also an authentication bypass problem affecting particular versions of FortiOS and FortiProxy. It also appears on the list of CISA known vulnerabilities.
South Korean investigators also found Gunra exploiting exposed VPN credentials and weak SSH access controls. In one case, attackers used default credentials on an SSL-VPN device. They then found an unused account that could reach both internal and external networks.
The attackers changed the account settings and used it to move deeper into the victim’s network.
The Ransomware First Steals Data before Encryption
Gunra does more than lock files and demand money. The group uses a double-extortion strategy. Attackers first steal sensitive information. They then encrypt important files and threaten to publish the stolen data.
The FBI saw Gunra steal business documents, databases, personal information and internal emails. In one case, attackers also accessed Microsoft OneDrive and SharePoint data. They compressed stolen information and moved it through services including Mega. The amount of stolen data reached tens of terabytes in at least one documented case.
With this approach, attackers have two ways by which they can pressure their victims. Even if the organization manages to restore backup files, the attackers can still extort them using the stolen data.
Gunra typically gives victims five to seven days to begin negotiations. Its ransom demands have started at amounts exceeding tens of millions of dollars, according to the advisory.
Attackers Also Target Backups
Gunra takes steps to make recovery harder. The ransomware can delete Windows shadow copies before encryption. In one case, attackers deleted backup and archived data at both the main data center and disaster recovery site.
The group also clears logs and command history to make its activity harder to spot. Investigators found that Gunra often performs reconnaissance late at night or early in the morning.
The Windows ransomware can encrypt files quickly across accessible drives. Encrypted files commonly receive the .ENCRT extension, while the ransom note is named R3ADM3.txt.
A Weakness may Help Linux Victims Recover
There is one unusual break for organizations hit by Gunra’s Linux version. Researchers found that some Linux samples use a weak method to create encryption keys. The process uses the system time as a starting point.
The advisory says defenders may be able to rebuild the keys using file timestamps. That could allow some victims to recover encrypted files without paying the ransom. However, organizations should preserve encrypted files, timestamps and system logs before attempting recovery.
Agencies Urge People to Observe Basic Defense Measures
The joint advisory puts strong emphasis on measures that can stop or limit a Gunra attack. Organizations should patch known exploited flaws on internet-facing systems. This would encompass VPN gateways, as well as infrastructure that has been made accessible using Remote Desktop capabilities.
Requiring multi-factor authentication as a standard practice across the board in the case of VPN, email, and any other accounts that have access to a company’s systems is a prudent security measure.
Breaking the network into segments also helps. In the event that an intruder actually breaches the security, segmentation would impede their activities considerably. In addition, organizations may have multiple backups and test their effectiveness against restoring systems.
The agencies also advise checking for unknown accounts and reviewing accounts with administrator rights.
They do not recommend paying a ransom. Payment does not guarantee that files will be recovered and can help fund further attacks. Organizations that suspect a Gunra infection ought to isolate affected systems, investigate the intrusion and report the incident to authorities.
This joint advisory is part of a broader South Korean strategy to combat cybercrime, the government recently announced a separate initiative to develop an integrated monitoring system to hunt down drug dealers operating on the dark web, with a dedicated investment to develop de-anonymization and AI-powered surveillance technologies.
The warning reflects a wider shift in ransomware. Groups no longer need to rely only on encryption. By stealing data first, they can keep pressure on victims even when recovery plans work.
Gunra’s move into an affiliate model makes that threat harder to contain. More criminals can use the same platform, while organizations across many industries remain potential targets.