Particle.news
Download on the App Store

U.S. and South Korea Warn of Gunra RaaS Recruiting Penetration Testers

The advisory warns the group now operates as a commercial ransomware-as-a-service recruiting penetration testers, urging organizations to patch systems, restrict external access, enforce multi-factor authentication.

Overview

  • U.S. and South Korean cyber agencies issued a joint advisory on Aug. 10–11 that published indicators and defensive steps after observing Gunra evolve into a formal ransomware-as-a-service operation.
  • Gunra now recruits penetration testers and ethical hackers to sell initial access to affiliates, offering profit shares in exchange for enterprise network entry.
  • The group targets government and critical infrastructure plus sectors such as health care, finance, manufacturing, education and utilities across regions including Asia-Pacific, Europe, the Americas and Africa.
  • Attackers exploit known flaws in internet-facing devices — researchers point to Fortinet and Schneider Electric vulnerabilities — use phishing and credential theft for access, and run a double-extortion scheme with a Tor leak site.
  • Analysts note technical overlaps with North Korean-linked tooling but say public evidence does not yet prove state sponsorship; agencies stress patching, limiting external access, MFA and cross-border investigation as priorities.