Washington, D.C.

Feds Warn Gunra Ransomware Gang Is Targeting US Critical Infrastructure

AI Assisted Icon
Published on August 11, 2026
Feds Warn Gunra Ransomware Gang Is Targeting US Critical InfrastructureSource: Unsplash/Towfiqu barbhuiya

A ransomware operation called Gunra is targeting victims across government, critical infrastructure, and multiple other sectors, according to a joint cybersecurity public service announcement issued this week. The gang encrypts victims' data and threatens to publish stolen files unless a ransom is paid, a tactic known as double extortion. The warning names government and infrastructure operators specifically as targets, a signal that the threat has moved beyond isolated corporate breaches.

The alert came from FBI Denver, whose FBI Denver account shared details of the advisory and said the bureau accepts public tips out of its Denver, Colorado office. The advisory itself, tracked as product ID AA26-222A and dated August 10, 2026, was issued jointly by the FBI, the Cybersecurity and Infrastructure Security Agency, the NSA, the U.S. Secret Service, the Department of Defense Cyber Crime Center, and South Korea's National Police Agency. That level of multi-agency, multinational coordination underscores how seriously officials are treating the group's expansion.

From a Single Strain to a Criminal Franchise

Gunra first emerged in April 2025 as a Windows-focused ransomware variant built on Conti source code that leaked in 2022, according to Picus Security. The group added a Linux version by mid-2025, and in January 2026 it launched a formal ransomware-as-a-service affiliate program, transforming from a single criminal strain into an open commercial model in roughly sixteen months. That commercialization has fueled a fast-moving recruitment drive.

To expand its dark-web operations, Gunra now operates under secondary branding such as Golden Community, offers affiliates an 80 percent cut of ransom payouts, and actively recruits ethical hackers and penetration testers to serve as initial access brokers who sell entry points into enterprise networks, according to CyberScoop. That affiliate structure helps explain why the group's victim count has climbed so quickly since its RaaS launch.

How Gunra Actors Break In

Joint federal findings show Gunra actors primarily breach target networks by exploiting authentication bypass vulnerabilities in Fortinet FortiOS and FortiProxy appliances, tracked as CVE-2024-55591 and CVE-2025-24472, along with a flaw in Schneider Electric PowerLogic P5 devices, CVE-2024-5559, per The Hacker News. CISA had previously alerted critical infrastructure operators about the unpatched Fortinet vulnerabilities, making the continued exploitation a warning sign for organizations that haven't applied the fixes. The same report notes that Ransomware.Live tracking data shows Gunra has listed 51 victim organizations on its leak site between April 2025 and this month, with most concentrated in South Korea, Brazil, Spain, Thailand, and Hong Kong, and only three victims identified in the U.S. and Canada. Once inside a network, Gunra encrypts victim files using multithreaded ChaCha20 or Salsa20 stream ciphers paired with RSA-4096 key exchange, according to the National Security Agency, which also notes the group clears command shell histories and deletes system and network access logs to cover its tracks. The multithreaded approach allows attackers to lock terabytes of data within minutes, leaving little time for defenders to respond once an intrusion is detected.

Multimillion-Dollar Demands and a Push on Executives

Ransom demands issued by Gunra actors frequently exceed $10 million, and victims are typically given five to seven days to enter a Tor-based negotiation panel before stolen data is posted or sold on public leak sites, according to the same report from The Record. The tight deadlines are designed to pressure victims into paying before they can fully assess the breach or restore from backups. The FBI has also observed Gunra operators bypassing internal IT departments altogether to send extortion emails directly to corporate executives and management staff, though the tactic has met with limited success, per the same account. Direct outreach to leadership is an aggressive escalation several modern ransomware groups have adopted to create panic at the top of an organization, sidestepping security teams who might otherwise intercept the threat.

A Silver Lining for Linux Victims

Not every part of Gunra's operation is airtight. A technical analysis highlighted in the official advisory revealed a severe cryptographic defect in Gunra's Linux variant, caused by a time-seeded random number generator, according to CISA. That flaw can allow victims to recover encrypted Linux files without paying a ransom, giving system administrators running Linux infrastructure a potential path to recovery that Windows victims don't share.

Separately, cybersecurity researchers in South Korea reported in July 2026 that Gunra actors shared operational tools and infrastructure with North Korea's state-sponsored Lazarus Group during campaigns targeting South Korean entities, The Record reports. The finding hints at possible cross-collaboration between financially motivated ransomware crews and nation-state hackers, though researchers characterized the connection with medium confidence rather than certainty.

Federal Guidance for Network Defenders

CISA Acting Executive Assistant Director Chris Butera said Gunra represents an ongoing threat to global infrastructure, urging organizations to immediately patch internet-facing VPN gateways and deploy offline, immutable backups that ransomware can't alter or delete, according to MeriTalk. That guidance echoes a pattern Hoodline has tracked across several ransomware incidents this year, including a malware-driven 911 outage in Suisun City and a data breach confirmed by San Francisco-based Levi Strauss amid what officials have called a global hacking wave.

While tracking data shows Gunra's victim pool has so far been concentrated heavily in Asia and Latin America, with only a handful of confirmed cases in North America, the joint advisory signals that U.S. sectors including healthcare, utilities, and government are now squarely in the group's crosshairs. Organizations that have not yet patched the named Fortinet and Schneider Electric vulnerabilities remain exposed to the same intrusion methods federal investigators say Gunra actors have repeatedly used to gain a foothold.