U.S., South Korea warn of Gunra ransomware targeting critical infrastructure
This digest was compiled by AI from multiple sources — links to the originals are below.

The U.S. Cybersecurity and Infrastructure Security Agency, FBI, and South Korea’s National Police Agency on Monday issued a joint alert detailing the operations of Gunra, a ransomware-as-a-service group that recruits ethical hackers and penetration testers as initial access brokers. Gunra has targeted organizations in government, healthcare, finance, and other critical sectors across six continents, using a double-extortion model to pressure victims. The alert follows the group’s rapid expansion after launching a formal affiliate program in January 2026.
Gunra’s Ransomware Operations
Gunra emerged as a double-extortion ransomware group in April 2025, posting stolen data on a Tor-based leak site. By January 2026, it had formalized a ransomware-as-a-service affiliate program, adopting the alias Golden Community. The group actively recruits penetration testers and ethical hackers to gain initial access to enterprise networks, offering them a cut of ransom profits. Gunra exploits known vulnerabilities in internet-facing devices like firewalls and VPNs, and its code is based on the leaked Conti ransomware source from 2022. Victims span academia, finance, government, healthcare, manufacturing, media, retail, transportation, and utilities.
North Korean Links and Global Alert
The joint advisory involved CISA, the Department of Defense Cyber Crime Center, FBI, NSA, U.S. Secret Service, and South Korea’s National Police Agency. Research by South Korean firm AhnLab in July 2026 found overlaps in tools and infrastructure between Gunra and the Lazarus Group, a North Korean state-sponsored hacking unit. While the groups appear to have different objectives, they likely shared techniques and collaborated to a limited extent, according to AhnLab. Such state-criminal collaboration dates back to at least 2024, and Gunra is not alone among ransomware groups in recruiting penetration testers. The alert is part of the #StopRansomware campaign.
What's Next
U.S. and South Korean agencies urge organizations to patch known vulnerabilities and monitor for Gunra activity. As the group continues to attract affiliates and leverage state-linked tools, defenders face a persistent and evolving threat.
2 sources
U.S., South Korea warn of Gunra ransomware targeting critical infrastructure



