conv.

All stories

CISA, FBI and South Korea warn of Gunra ransomware hitting critical infrastructure

A joint advisory says the Conti-derived RaaS gang is exploiting known Fortinet flaws to breach healthcare, finance and government networks worldwide.

CISA, FBI and South Korea warn of Gunra ransomware hitting critical infrastructure
theregister.com

Conversation activity · last 32 hours peak 6/30m

Peak 6 items in one 30m at Aug 10, 1 PM; 17 items over 32 hours Aug 10, 1:06 PM — 6 items · Google News 6Aug 10, 1:36 PM — no itemsAug 10, 2:06 PM — no itemsAug 10, 2:36 PM — no itemsAug 10, 3:06 PM — no itemsAug 10, 3:36 PM — no itemsAug 10, 4:06 PM — no itemsAug 10, 4:36 PM — no itemsAug 10, 5:06 PM — no itemsAug 10, 5:36 PM — no itemsAug 10, 6:06 PM — no itemsAug 10, 6:36 PM — no itemsAug 10, 7:06 PM — no itemsAug 10, 7:36 PM — no itemsAug 10, 8:06 PM — no itemsAug 10, 8:36 PM — no itemsAug 10, 9:06 PM — no itemsAug 10, 9:36 PM — no itemsAug 10, 10:06 PM — no itemsAug 10, 10:36 PM — no itemsAug 10, 11:06 PM — no itemsAug 10, 11:36 PM — no itemsAug 11, 12:06 AM — no itemsAug 11, 12:36 AM — no itemsAug 11, 1:06 AM — no itemsAug 11, 1:36 AM — no itemsAug 11, 2:06 AM — no itemsAug 11, 2:36 AM — no itemsAug 11, 3:06 AM — no itemsAug 11, 3:36 AM — no itemsAug 11, 4:06 AM — no itemsAug 11, 4:36 AM — no itemsAug 11, 5:06 AM — no itemsAug 11, 5:36 AM — 1 item · Press 1Aug 11, 6:06 AM — no itemsAug 11, 6:36 AM — no itemsAug 11, 7:06 AM — no itemsAug 11, 7:36 AM — no itemsAug 11, 8:06 AM — 6 items · Google News 6Aug 11, 8:36 AM — no itemsAug 11, 9:06 AM — no itemsAug 11, 9:36 AM — no itemsAug 11, 10:06 AM — 1 item · Press 1Aug 11, 10:36 AM — no itemsAug 11, 11:06 AM — no itemsAug 11, 11:36 AM — no itemsAug 11, 12:06 PM — 1 item · Mastodon 1Aug 11, 12:36 PM — 1 item · Hacker News 1Aug 11, 1:06 PM — no itemsAug 11, 1:36 PM — no itemsAug 11, 2:06 PM — no itemsAug 11, 2:36 PM — no itemsAug 11, 3:06 PM — no itemsAug 11, 3:36 PM — no itemsAug 11, 4:06 PM — no itemsAug 11, 4:36 PM — no itemsAug 11, 5:06 PM — no itemsAug 11, 5:36 PM — no itemsAug 11, 6:06 PM — no itemsAug 11, 6:36 PM — no itemsAug 11, 7:06 PM — no itemsAug 11, 7:36 PM — no itemsAug 11, 8:06 PM — 1 item · Mastodon 1Aug 11, 8:36 PM — no items 6 items · 1:06 PM
4 PMAug 118 AM4 PMnow · 9:06 PM

Summary, timeline and people extracted by Claude from 17 items across 4 sources · 2h ago. Quotes are verbatim.

US cybersecurity agencies and South Korea's National Police Agency issued a joint advisory on August 10, 2026 warning that Gunra ransomware affiliates are exploiting two known Fortinet authentication-bypass vulnerabilities to breach critical infrastructure organizations. The group, which emerged in April 2025 using leaked Conti source code, now runs as a ransomware-as-a-service operation practicing double extortion, with victims given five to seven days and demands often exceeding $10 million before stolen data is published.

  • Six agencies — CISA, FBI, NSA, Secret Service, DoD Cyber Crime Center and South Korea's National Police Agency — issued a joint advisory on Gunra ransomware on August 10, 2026.
  • Gunra affiliates exploit known Fortinet authentication-bypass flaws (CVE-2024-55591, CVE-2025-24472) to gain administrative access to internet-facing devices.
  • The group uses a double-extortion model, giving victims five to seven days before publishing stolen data, with ransom demands often exceeding $10 million.
  • Gunra, built on leaked Conti source code and active since April 2025, now operates as ransomware-as-a-service, recruiting affiliates under aliases including 'Golden Community'; a flaw in its Linux variant can let some victims recover files without paying.

How it unfolded

  1. Follow-up reporting reiterated agency guidance to patch known exploited vulnerabilities, secure VPN/RDP access with MFA, segment networks, and keep offline immutable backups.

  2. Outlets highlighted an advisory finding that Gunra's Linux variant contains a weakness letting defenders reconstruct encryption keys from file timestamps without paying ransom.

  3. CISA, the FBI, NSA, Secret Service, DoD Cyber Crime Center and South Korea's National Police Agency warned that Gunra affiliates exploit CVE-2024-55591 and CVE-2025-24472 in Fortinet FortiOS/FortiProxy to gain administrative access before stealing and encrypting data.

    “Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations”

    Chris Butera, CISA acting executive assistant director for cybersecurity · Google News ↗
  4. Dragos said it identified 1,140 ransomware incidents against industrial organizations in Q2 2026, a 12% rise from Q1, with at least four attributed to Gunra after eight in Q1.

  5. 2 weeks quiet
  6. Researchers reported that tools and infrastructure used by North Korea's Lazarus Group appear shared with Gunra as it targeted South Korean organizations.

  7. 30 weeks quiet
  8. The FBI says Gunra moved to a RaaS model and was seen recruiting new affiliates on cybercriminal forums.

  9. 39 weeks quiet
  10. Gunra emerges targeting Windows systems, built using source code leaked from the Conti ransomware operation.

What people are saying verbatim

“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations”

Chris Butera, CISA acting executive assistant director for cybersecurity · The Record from Recorded Future News ↗ · Aug 9

“With our partners, CISA encourages organizations to urgently mitigate vulnerabilities identified in this advisory, implement recommended actions, and adopt security measures aligned to CPGs”

Chris Butera, CISA acting executive assistant director for cybersecurity · MeriTalk ↗ · Aug 9

“The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments with limited success”

FBI advisory, Joint cybersecurity advisory · The Record from Recorded Future News ↗ · Aug 9

“reconstruct the keys using file timestamps and recover files without paying the ransom”

Joint advisory, Cybersecurity advisory finding · The Record from Recorded Future News ↗ · Aug 9