US and South Korea warn of Gunra ransomware targeting govt agencies

US and South Korea warn of Gunra ransomware targeting govt agencies
U.S. and South Korean agencies warned that Gunra ransomware is targeting government and critical infrastructure organizations worldwide, using Conti-based code, Fortinet firewall exploits, and other access flaws to spread across Windows and Linux systems. The advisory also notes Gunra’s shift to a ransomware-as-a-service model, its recruitment of initial access brokers, and possible links to Lazarus Group. #Gunra #Conti #Fortinet #FortiOS #FortiProxy #LazarusGroup

Keypoints

  • Gunra ransomware is targeting government and critical infrastructure organizations worldwide.
  • The group uses code derived from leaked Conti ransomware source code.
  • Attackers exploit Fortinet firewall flaws and VPN security weaknesses for initial access.
  • Gunra expanded from Windows-focused attacks to cross-platform campaigns with a Linux variant.
  • The gang launched a RaaS program and may be linked to Lazarus Group.

Read More: https://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/