Techtimes
Gunra Ransomware Targets Hospitals and Governments, Exploits Critical Vulnerabilities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Gunra ransomware, a ransomware-as-a-service derived from Conti code, has attacked at least 51 organizations globally, including hospitals and government agencies. The group exploits critical vulnerabilities in Fortinet firewall products (CVE-2024-55591 and CVE-2025-24472) to gain access. Ransom demands often exceed $10 million, with Linux victims potentially able to recover files without payment due to a cryptographic flaw. The ransomware has been active since April 2025 and has expanded its operations to include a formal RaaS model. A joint advisory from six U.S. and South Korean agencies warns of the ongoing threat and the need for immediate patching of affected systems. Organizations are urged to secure their networks against these sophisticated attacks.
Key Points: • Gunra ransomware has impacted over 51 organizations worldwide, including hospitals and governments. • Attackers exploit critical vulnerabilities in Fortinet products (CVE-2024-55591, CVE-2025-24472) for initial access. • Linux victims may recover encrypted files without paying ransom due to a cryptographic flaw in the ransomware.