FBI and South Korea Warn of Gunra Ransomware Targeting Critical Infrastructure
The FBI and South Korea's government have issued a warning about the Gunra ransomware gang, which is targeting critical infrastructure organizations by exploiting vulnerabilities in popular firewall products from Fortinet. The ransomware operation, which emerged in April 2025, uses source code from the Conti ransomware. Gunra actors have been exploiting vulnerabilities CVE-2024-55591 and CVE-2025-24472 to gain privileged access, steal, and encrypt data before extorting organizations. The group has targeted sectors such as healthcare, financial services, and government, demanding ransoms exceeding $10 million.