US and Korean agencies warn about Gunra, a fast-growing ransomware gang built from leaked Conti code

The FBI, CISA and Korea's National Police Agency say Gunra has hit hospitals, utilities and manufacturers across five continents since April 2025.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A network operations center with rows of monitors displaying threat alerts and geographic heat maps, red indicators pulsing across continents as analysts in the
Share

Key points

  • The FBI, CISA, NSA, Secret Service, DC3 and the Republic of Korea's National Police Agency issued a joint advisory on Gunra ransomware on August 10, 2026.
  • Gunra first appeared in April 2025 and launched a formal affiliate program, sometimes branded Golden Community, in January 2026.
  • The gang breaks in mainly by exploiting Fortinet firewall and VPN bugs, including CVE-2024-55591 and CVE-2025-24472.
  • Victims are given 5 to 7 days to negotiate over a Tor site and the encrypted chat app qTox before stolen data is auctioned.
  • Gunra's code is based on the Conti ransomware source code that leaked in 2022, and now runs on both Windows and Linux.

Six government agencies have joined up to warn businesses about a ransomware crew called Gunra, which has built one of the busier extortion operations of the past year.

Ransomware is malicious software that scrambles a company's files so nobody can open them, then demands payment for the key. Gunra adds a second squeeze: it steals the files first and threatens to publish them on a dark web site if the victim won't pay.

The joint advisory from CISA, the FBI, the NSA, the Secret Service, the Defense Department's Cyber Crime Center and the Republic of Korea's National Police Agency landed on August 10, 2026, as part of the ongoing #StopRansomware series.

Who is Gunra and where did they come from?

Gunra is a criminal group that rents its ransomware to other criminals, a model the industry calls ransomware-as-a-service. The FBI first spotted the malware in April 2025. By January 2026 the group had opened a formal affiliate program on dark web forums, complete with a builder and cross-platform payloads. It's also operated under the alias Golden Community.

The code isn't new work. Investigators say Gunra is built on the Conti source code, which spilled onto the internet in 2022 after Conti's internal chats were leaked. That leak has been the gift that keeps giving for copycats.

How are the criminals getting in?

Mostly through unpatched firewalls and VPN boxes sitting on the public internet. A VPN, or virtual private network, is the encrypted tunnel staff use to reach work systems remotely. If the box running that tunnel has a known bug, attackers walk straight through it.

The FBI names two Fortinet flaws in particular:

CVE Product What it does
CVE-2024-55591 FortiOS, FortiProxy Lets an attacker skip the login
CVE-2025-24472 FortiOS, FortiProxy Lets an attacker skip the login

Korean investigators also saw affiliates using exposed credentials and weak SSH settings on VPN gateways. SSH is the remote-login tool administrators use to manage servers. Fortinet edge devices were already on our radar: we reported in July that CISA gave federal agencies a weekend to patch two Fortinet flaws already under active attack.

Edge devices are hard to patch and easy to forget. They also sit in front of everything valuable.

What happens to a victim?

Once inside, the malware walks every drive encrypting files as it goes. It drops a ransom note in every folder pointing the victim to a Tor site, where they're handed a Client ID and password, then told to negotiate on qTox within 5 to 7 days. Miss the window and the stolen data goes up for sale.

Victims listed on Gunra's leak site span healthcare, banking, manufacturing, transport, utilities, government and media, across the Americas, Europe, the Middle East, Africa and the Asia-Pacific. Gunra started Windows-only but added a Linux variant in mid-2025, which matters because most business servers run Linux.

Should ordinary people worry?

Not directly, but the knock-on effects are real. When a hospital or utility gets hit, patients get appointments cancelled and staff data ends up on a leak site. If your employer tells you your information was in a Gunra breach, treat it seriously: change reused passwords, enable two-step login, and watch for phishing emails referencing the incident.

For defenders, the advisory's guidance maps neatly to what we've tracked all summer across 16 ransomware stories in the last 30 days: patch your edge boxes now, keep offline backups you've actually tested, and segment your network so one compromised laptop isn't a free pass to the file servers.

© 2026 Threat Vectr