Korea and U.S. issue joint advisory on Gunra ransomware attacks

South Korean and U.S. authorities have issued a joint cybersecurity advisory warning that Gunra, a ransomware strain first seen in 2025, has developed into a ransomware-as-a-service operation targeting government, critical infrastructure, finance, health care and manufacturing. The advisory, published August 11, 2026, says Gunra has hit at least 51 organizations across the Americas, Europe, the Middle East, Africa and the Asia-Pacific, with many documented ransom demands above $10 million. Investigators said the Conti-derived group mainly gained access by exploiting Fortinet FortiOS and FortiProxy authentication-bypass flaws CVE-2024-55591 and CVE-2025-24472, though cases also involved default SSL-VPN credentials, stolen session cookies and tampering with MFA systems. The agencies urged organizations to patch internet-facing systems, restrict external access, rotate credentials, strengthen MFA, isolate backups and preserve encrypted Linux files because a cryptographic weakness in Gunra's Linux encryptor may allow some .GNRA files to be recovered without paying if timestamps are intact.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.