Overview
- U.S. and South Korean cyber agencies issued a joint advisory on Aug. 10–11 that published indicators and defensive steps after observing Gunra evolve into a formal ransomware-as-a-service operation.
- Gunra now recruits penetration testers and ethical hackers to sell initial access to affiliates, offering profit shares in exchange for enterprise network entry.
- The group targets government and critical infrastructure plus sectors such as health care, finance, manufacturing, education and utilities across regions including Asia-Pacific, Europe, the Americas and Africa.
- Attackers exploit known flaws in internet-facing devices — researchers point to Fortinet and Schneider Electric vulnerabilities — use phishing and credential theft for access, and run a double-extortion scheme with a Tor leak site.
- Analysts note technical overlaps with North Korean-linked tooling but say public evidence does not yet prove state sponsorship; agencies stress patching, limiting external access, MFA and cross-border investigation as priorities.