Protect.Computer
NEWS

FBI Warns of Gunra Ransomware Targeting Critical Infrastructure

· 1 min read · Got hacked Network safety
FBI Warns of Gunra Ransomware Targeting Critical Infrastructure

The FBI, South Korea’s National Police Agency, and CISA issued a joint advisory Monday warning that the Gunra ransomware gang is actively breaching critical infrastructure organizations around the world. Gunra emerged in April 2025 and is built using the Conti ransomware source code that leaked publicly in 2022. The group initially targeted Windows environments but has since developed a Linux variant and transitioned to a ransomware-as-a-service (RaaS) model, recruiting initial access brokers on criminal forums under the alias “Golden Community.” Researchers have also observed infrastructure and tooling overlap with North Korea’s Lazarus Group, suggesting some operational sharing between the two groups.

The advisory identifies two specific vulnerabilities that Gunra actors are exploiting to gain privileged access before stealing and encrypting data: CVE-2024-55591 and CVE-2025-24472, both affecting Fortinet firewall products. Victims in the healthcare, financial services, and government sectors have received ransom demands exceeding $10 million and five-to-seven-day payment windows. The FBI said the group has attempted to contact management staff directly by email to negotiate payments, with limited success. There is a silver lining for organizations already hit by the Linux variant: as of March 2026, researchers found a weakness in Gunra’s Linux encryption scheme that allows defenders to reconstruct decryption keys from file timestamps and recover encrypted files without paying the ransom. CISA and the FBI are sharing indicators of compromise and detection guidance with government and private-sector partners through the advisory.

How to check if you’re affected

Affected versions of Fortinet FortiGate include those vulnerable to CVE-2024-55591 and CVE-2025-24472 — check your appliance’s firmware version against Fortinet’s security advisories for both CVEs and apply the available patches immediately. Organizations that run Fortinet firewalls at the perimeter of healthcare, financial, or government networks should audit VPN and management interface logs for signs of unauthorized privileged access. Indicators of compromise from the joint advisory are available at cisa.gov; feed them into your SIEM and threat-intelligence platform now. If you suspect you have already been compromised by the Linux variant, do not pay the ransom before consulting the advisory’s decryption guidance — the encryption weakness may allow recovery without payment.

Sources

Related reading