GadgetLad’s Alert: Gunra on the Rampage
US cybersecurity experts are advising the critical infrastructure crew to get their internet-facing systems updated, as Gunra ransomware affiliates are creating havoc by taking advantage of known vulnerabilities to infiltrate networks. This malicious entity first appeared on the radar in 2025 and has swiftly escalated its mayhem.
The Emergence of Gunra
CISA, the FBI, NSA, Secret Service, and their counterparts in South Korea are reporting that it now operates as ransomware-as-a-service. The affiliates are on a worldwide rampage, targeting healthcare, financial services, government entities, professional services, nonprofits, and other vital infrastructure. They have been exploiting CVE-2024-55591 and CVE-2025-24472—authentication bypass vulnerabilities in Fortinet’s FortiOS and FortiProxy—to obtain admin access via those internet-exposed devices.
Gunra’s Sinister Strategy
Once they gain access, these Gunra criminals adhere to the familiar double-extortion tactics: steal data, lock systems down tighter than a drum, and then demand a hefty ransom for a decryption key and a promise not to release the stolen data online. Negotiations occur through a Tor-based site, with victims given only five to seven days to pay up before their information is paraded on the web like a bad joke.
From Windows to Linux Shenanigans
“Gunra is just another name on the long list of ransomware attacks wreaking havoc everywhere,” stated Chris Butera, CISA’s acting executive assistant director for cybersecurity. Trend Micro first detected Gunra in April 2025, initially targeting Windows systems and adopting a few methods from the Conti ransomware gang. Subsequently, a Linux variant emerged, proving it could compromise a broader array of systems.
Global Gunra Carnage
This Linux variant can operate up to 100 encryption threads simultaneously and can partially encrypt, allowing attackers to decide how much of a specific file to meddle with. It can also secure RSA-encrypted keys in separate keystore files. Trend Micro has observed Gunra activity in Turkey, Taiwan, the US, and South Korea. However, the gang’s leak site has a broader reach, claiming victims in Brazil, Japan, and Canada, including manufacturers, healthcare providers, IT firms, and law offices.
GadgetLad’s Concluding Thoughts
The agencies are urging potential targets to patch known exploited vulnerabilities in internet-facing systems, secure VPN gateways and RDP access with multi-factor authentication, segment networks, and maintain offline, immutable backups. Make it a bit more challenging for the rogue actors seeking to breach your defenses.
Summary: “Update, or Else!”
So there you have it, folks. Keep your systems current, or Gunra may just drop by uninvited. There’s no reason to roll out the welcome mat for these troublemakers; just update and stay secure!