US, South Korea Warn of Growing Gunra Ransomware Threat
ID: b0e2b49f-6bad-5d36-9a2c-24612cfbdaec
STIX ID: report--b0e2b49f-6bad-5d36-9a2c-24612cfbdaec
Feed Name: TechRepublic Security
Gunra is a rapidly evolving ransomware operation that appeared in South Korea in April 2025 and has grown into an international ransomware-as-a-service campaign affecting at least 32 organizations by March 2026; it uses leaked Conti code initially, later developed its own cross-platform (Windows and Linux) ransomware, employs double-extortion data theft, and leverages affiliates to scale attacks against government and critical infrastructure. The advisory emphasizes familiar defenses — patching, reducing internet-facing exposure, strong authentication, network segmentation, monitoring for lateral movement and data exfiltration, and isolated backups — to reduce impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
