Hacking

Gunra Ransomware Attacks Target Critical Infrastructure

Published  ·  7 min read

A Warning about Gunra Ransomware Threats on Critical Infrastructure Sectors across the worldwide Issued by South Korean and US Cyber Security and Intelligence Agencies. The attacks have hit healthcare, financial services, government facilities, and professional services across multiple countries.

"Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations," said Chris Butera, CISA Acting Executive Assistant Director for Cybersecurity.

The Gunra ransomware attacks exploit vulnerabilities in internet-facing Schneider Electric PowerLogic P5 and Fortinet FortiOS and FortiProxy appliances to gain initial access. Once inside, the attackers deploy the ransomware as part of a double extortion model that combines data exfiltration with encryption.

Now let me introduce you to the Gunra ransomware attacks, the techniques employed by the attackers, and how organizations can protect themselves against such attacks.

Scale of Gunra Ransomware Attacks

The attacks conducted by the Gunra ransomware have targeted 51 victims in April 2025. Most of the victims of the attacks have been from South Korea, Brazil, Spain, Thailand, and Hong Kong. Most of the victims have been from Australia, East Asia, and Europe, with only three from Canada and the US.

Victims who refuse to pay the ransom within five to seven days have their stolen data published on a leak site. This double extortion pressure is designed to maximize the chances of payment.

The RaaS Affiliate Program

The Gunra ransomware attacks are operated by a Conti-derived group that launched a formal Ransomware-as-a-Service affiliate program on dark web forums in January 2026. Affiliates are provided with:

  • A management panel for controlling infections
  • A configurable ransomware builder
  • Cross-platform locker payloads for Windows and Linux
  • Structured affiliate documentation

The group offers both Windows and Linux variants of its locker. However, researchers at Breakglass Intelligence identified a "catastrophic cryptographic weakness" in the Linux builds that made it possible to recover the encryption key without paying the ransom.

Phishing As the Major Attack Vector

The Gunra attacks involve the heavy use of phishing attacks as the major vector for executing their attacks. The group delivers malicious payloads to their victims using effective phishing campaigns and performs ransom negotiations via WhatsApp-like chat panel.

The group is capable of encrypting massive amounts of data quickly. It has been noticed that the ransomware is able to encrypt up to 9 terabytes within a short period of time due to the use of high-speed stream cipher encryption techniques like Salsa20 and ChaCha20. This speed makes the Gunra ransomware attacks particularly destructive.

New Branding and Recruitment

Brandings of the Gunra ransomware attacks have changed in that they now use new brandings like Golden Community among others in order to increase their reach. The Gunra ransomware group is looking for penetration testers and ethical hackers to serve as initial access brokers. These brokers are offered a share of the ransom profits in exchange for providing access to enterprise networks.

This recruitment strategy indicates that the Gunra ransomware attacks are becoming more organized and professionalized.

Lateral Movement and Credential Theft

The Gunra ransomware attacks use Impacket libraries for lateral movement. The attackers use psexec.py and smbclient.py to move through networks using the Server Message Block protocol. They also use secretsdump.py to perform credential dumping against compromised domain controllers.

The attackers extract password hashes of user accounts from the NT Directory Services file. They then delete system and network access logs, clear command history, and conduct most malicious activities between 10 p.m. and 6 a.m. to avoid detection.

Data Exfiltration Tactics

Data exfiltration in the Gunra ransomware attacks is accomplished using an executable named "main.exe." The attackers target Microsoft OneDrive and SharePoint for data theft.

In some cases, the Gunra ransomware attacks have created compressed archives containing terabytes of data and exfiltrated them to the MEGA file-sharing service. The group also connects to virtual desktop infrastructure environments of IT personnel to harvest sensitive documents containing system and network configuration information.

SSL-VPN Manipulation and MFA Bypass

One of the most sophisticated aspects of the Gunra ransomware attacks is the manipulation of SSL-VPN appliances. In a case spotted by South Korea's National Police Agency, the attackers manipulated the network traffic control functionality of an SSL-VPN appliance to intercept credentials and session information transmitted by users authenticating to a corporate VDI portal.

The stolen session cookies were then used for session hijacking, allowing the attackers to impersonate legitimate users and gain access to the internal network.

To bypass multi-factor authentication, the Gunra ransomware attacks tampered with authentication processing files on the corporate VDI authentication portal server. This enabled successful authentication when a specific, attacker-designated one-time password value was entered.

Other Detected Behaviors

  • The Gunra ransomware attacks have exhibited several other sophisticated behaviors:
  • Gaining access to SSL-VPN administrator accounts by exploiting default credentials
  • Downloading OpenSSH from attacker-controlled servers to maintain persistence
  • Modifying SSL-VPN account configurations to avoid mandatory password changes
  • Accessing system access control servers to steal symmetric encryption keys
  • Deleting backup data at both primary and disaster recovery centers

The North Korea Connection

The Gunra ransomware attacks share significant overlap with campaigns attributed to North Korean state-sponsored threat groups. Some incidents involving the exploitation of financial security software vulnerabilities have been linked to both state-sponsored actors and Gunra.

Watering hole attacks have exploited a zero-day vulnerability in AnySign4PC, deploying malware on systems with the certificate signing software installed. Payloads include Struggle and Brandoor, both known tools of the Lazarus Group.

AhnLab stated: "These commonalities suggest that although the state-sponsored threat group and the Gunra ransomware group appear to be separate threat actors with different ultimate objectives, they may have shared certain techniques, tools, and infrastructure or collaborated to a limited extent during the attacks."

This kind of collaboration between North Korean nation-state groups and ransomware operators is not unprecedented. In October 2024, Palo Alto Networks Unit42 observed the Lazarus sub-cluster Andariel partnering with the Play ransomware crew.

What Organizations Should Do

To prevent Gunra ransomware attacks on their networks, organizations need to undertake the following steps:

  • Maintain all the operating systems, software, and firmware in an up-to-date state
  • Give priority to patching any known exploited vulnerabilities on internet-facing devices
  • Implement network segmentation
  • Backups should always be immutable and physically stored separately
  • Check SSL-VPNs for any tampering
  • Watch out for abnormal SSH behavior and credential dumping
  • Enable multi-factor authentication with phishing-resistant factors

Wrapping It Up

The Gunra ransomware attacks constitute a sophisticated threat that continues to evolve against critical infrastructure sectors worldwide. It is evident that the group uses a dual extortion approach and has targeted 51 different victims since April 2025, while growing through their affiliates.

Exploits are leveraged by the attackers on vulnerabilities within the Fortinet and Schneider Electric devices in order to access the network. The use of the Impacket libraries helps in facilitating lateral movement, searching cloud storage systems in order to exfiltrate data and other abilities include SSL-VPN manipulation and MFA bypass.

It is noted that there are indications of collaboration between the Gunra ransomware attacks and North Korea sponsored threat actors. Organizations should prioritize patching, network segmentation, and immutable backups to defend against this threat.

FAQ Section

What is Gunra Ransomware Attack?

It is an attack on ransomware where the critical infrastructure sectors like the healthcare sector, the financial sector, and governments get attacked by the ransomware. This ransomware attack is based on double extortion model , which involves data theft and encryption.

What is the entry point for the attackers?

The attackers leverage the vulnerabilities present in Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS and and FortiProxy (CVE-2025-24472) appliances.

What is the double extortion model?

The attackers exfiltrate data before encrypting it. Victims who refuse to pay within five to seven days have their data published on a leak site.

How does the group bypass MFA?

The Gunra ransomware attacks have tampered with authentication processing files on VDI portal servers, enabling successful authentication when a specific, attacker-designated OTP value is entered.

Is Gunra connected to North Korea?

The group shows signs of collaboration with North Korean state-sponsored threat actors. AhnLab noted they may have shared techniques, tools, and infrastructure or collaborated to a limited extent.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067