FBI, South Korea warn of Gunra ransomware targeting critical infrastructure

The FBI and South Korea's National Policy Agency have warned of a ransomware gang called Gunra that is breaching critical infrastructure organizations through firewall vulnerabilities, according to a joint cybersecurity advisory released Monday. The group, which emerged in April 2025 using source code from the leaked Conti ransomware, has been exploiting two known Fortinet firewall vulnerabilities to gain access to networks in the healthcare, financial services and government sectors globally, stealing and encrypting data before demanding ransoms often exceeding $10 million.
The agencies said Gunra actors have attempted to contact victim company management directly by email to solicit payments, with limited success, The Record reports.