The Gunra ransomware group is exploiting Fortinet firewall vulnerabilities to breach critical infrastructure organizations, steal data, and encrypt systems before demanding multi-million-dollar ransoms. U.S. and South Korean authorities warned that Gunra, a Conti-derived operation, is expanding globally and targeting healthcare, financial services, and government sectors. #Gunra #Fortinet #Conti #CISA #FBI #LazarusGroup
Keypoints
- Gunra is targeting critical infrastructure through Fortinet firewall vulnerabilities.
- The group uses stolen and encrypted data to pressure victims into paying ransom.
- Authorities say Gunra was built from leaked Conti source code.
- The ransomware gang is targeting healthcare, finance, and government organizations worldwide.
- Gunra has shifted to a ransomware-as-a-service model and is recruiting new members.
Read More: https://therecord.media/ransomware-south-korea-fbi-gunra