logo

FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

ID: d2a6344e-c602-50f3-a757-09929c2194aa

STIX ID: report--d2a6344e-c602-50f3-a757-09929c2194aa

Feed Name: The Record from Recorded Future News

Threat Score
78/100

Date Published: 2026-08-10

Date Updated: 2026-08-19

...
...

U.S. and South Korean agencies warned that the Gunra ransomware group — built from leaked Conti code and now operating as a Ransomware-as-a-Service — is actively exploiting Fortinet firewall vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to breach healthcare, financial, government and industrial organizations, steal and encrypt data, and issue multimillion-dollar ransom demands; the advisory also notes tool-sharing links to Lazarus and that a weakness in Gunra's Linux variant can allow defenders to recover files without paying.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.