U.S. and South Korean agencies warned that Gunra ransomware is targeting government and critical infrastructure organizations worldwide, using Conti-based code, Fortinet firewall exploits, and other access flaws to spread across Windows and Linux systems. The advisory also notes Gunra’s shift to a ransomware-as-a-service model, its recruitment of initial access brokers, and possible links to Lazarus Group. #Gunra #Conti #Fortinet #FortiOS #FortiProxy #LazarusGroup
Keypoints
- Gunra ransomware is targeting government and critical infrastructure organizations worldwide.
- The group uses code derived from leaked Conti ransomware source code.
- Attackers exploit Fortinet firewall flaws and VPN security weaknesses for initial access.
- Gunra expanded from Windows-focused attacks to cross-platform campaigns with a Linux variant.
- The gang launched a RaaS program and may be linked to Lazarus Group.