Cyberscoop
Gunra Ransomware Gang Targets Global Infrastructure, U.S. and South Korea Issue Warning
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
U.S. and South Korean cyber agencies issued a warning regarding the Gunra ransomware gang, which recruits ethical hackers and uses North Korean hacking tools. Gunra targets various sectors, including government, healthcare, and financial services, with a double-extortion model that encrypts and threatens to leak data. The group has expanded its operations since its emergence in 2025, establishing a ransomware-as-a-service model in 2026. Gunra's tactics involve exploiting known vulnerabilities in internet-facing devices, influenced by the leaked Conti ransomware code. The FBI first identified Gunra in April 2025, and recent research suggests connections to the Lazarus Group, indicating potential collaboration. The advisory is part of the ongoing #StopRansomware initiative aimed at protecting organizations from such threats.
Key Points: • Gunra ransomware gang targets critical sectors globally, including government and healthcare. • The group employs a double-extortion model, threatening to leak stolen data. • Gunra has connections to North Korean hacking tools and tactics, indicating state-sponsored links.