CISA NSA FBI and South Korean Police Issue Joint Advisory on Gunra Ransomware Targeting Critical Infrastructure
The FBI, CISA, NSA, DOD Cyber Crime Center, US Secret Service, and South Korea's National Police Agency issued a joint advisory on Monday detailing Gunra ransomware, first observed by the FBI in April 2025 and derived from leaked
The advisory reads less as novel disclosure than as a patching mandate: both exploited FortiOS/FortiProxy flaws have been public over a year, so continued compromise reflects unremediated exposure rather than new attack surface. A lagging population of unpatched appliances rather than any new Gunra capability could equally explain the pattern. Gunra's shift into a structured RaaS model, with recruited penetration testers acting as access brokers, lowers the technical bar for follow-on intrusions against that same unpatched base, compounding risk for operators still running default credentials or unsegmented VPN and VDI environments. The tens-of-terabyte OneDrive and SharePoint exfiltration case shows double extortion now reaching cloud collaboration platforms, not just on-premises file shares. CISA's advisory is the sole primary source; other outlets merely republish it.
4 sources
- #StopRansomware: Gunra Ransomware -
CISA - FBI warns Gunra ransomware targets critical sectors and governments -
Cyber Insider - Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure -
The Register - CISA, FBI Warn Gunra Ransomware Actors Targeting Critical Infrastructure -
HSToday