Joint Advisory Issued
The Federal Bureau of Investigation (FBI) and the South Korean government have issued a joint cybersecurity advisory warning of active attacks by the Gunra ransomware gang against critical infrastructure organizations worldwide.
The advisory identifies Gunra as a financially motivated threat actor targeting sectors including energy, healthcare, water treatment, and telecommunications — using vulnerabilities in widely deployed firewall products as their primary initial access vector.
Who Is Gunra?
Gunra is a ransomware operation first identified in late 2025 that has rapidly expanded its targeting scope in 2026. The group operates a Ransomware-as-a-Service (RaaS) model, employing affiliates who conduct intrusions while the core group maintains the ransomware infrastructure and negotiation platform.
Key Characteristics
| Attribute | Detail |
|---|---|
| Type | Ransomware-as-a-Service (RaaS) |
| Model | Double extortion |
| Primary targets | Critical infrastructure sectors |
| Initial access | Firewall and VPN vulnerabilities |
| Geographic scope | Global, with focus on US and South Korea |
| First observed | Late 2025 |
Attack Methodology
Initial Access: Firewall Exploitation
The FBI advisory highlights that Gunra affiliates are gaining initial access by exploiting known and zero-day vulnerabilities in popular firewall brands commonly deployed at network perimeters. The advisory does not name specific vendors or CVEs in the public version, but notes that organizations running unpatched perimeter devices are at highest risk.
This mirrors a broader trend: ransomware groups disproportionately targeting edge devices (firewalls, VPNs, remote access gateways) because:
- They are internet-facing by design
- Patches are often delayed in operational environments
- Successful exploitation grants network-level access, bypassing endpoint detection
Post-Compromise Activity
Once inside the network, Gunra affiliates follow a well-documented playbook:
Initial Access (Firewall CVE)
↓
Establish persistence (backdoors, legitimate admin tools)
↓
Lateral movement (credential harvesting, internal recon)
↓
Data exfiltration (days to weeks before encryption)
↓
Ransomware deployment (StormEncryptor-class payload)
↓
Ransom demand (double extortion: pay or data published)
Double Extortion
Gunra's hallmark is exfiltrating sensitive data before deploying ransomware. This ensures the gang has leverage even if victims restore from backups:
- Encryption — Operational systems are encrypted, causing immediate disruption
- Leak threat — Stolen data is threatened to be published on Gunra's data leak site if ransom is not paid
For critical infrastructure operators, data leaks can include industrial system configurations, employee records, and sensitive operational data.
Targeted Sectors
The joint advisory specifically calls out the following critical infrastructure sectors as active targets:
Energy and Power
Disruption of energy infrastructure has outsized impact on both operational continuity and public safety. Gunra is reported to have conducted reconnaissance against energy sector targets in multiple countries.
Healthcare
Hospitals and healthcare networks remain high-value targets — both because they hold sensitive patient data and because operational disruption creates immediate safety risk, increasing pressure to pay.
Water and Wastewater
Water treatment facilities managing industrial control systems (ICS/OT environments) face particular risk. Ransomware in OT environments can have physical consequences.
Telecommunications
Telco infrastructure breaches can enable further downstream attacks and provide high-value data exfiltration targets.
Defensive Recommendations
The advisory provides the following priority defensive actions:
Immediate Actions
- Patch perimeter devices — Prioritize firewall and VPN patching; treat unpatched edge devices as compromised until verified
- Enable MFA on all remote access portals and VPN endpoints
- Audit firewall configurations — Remove legacy rules, restrict management interfaces to trusted IPs
- Segment OT networks — Ensure operational technology environments cannot be reached from corporate IT networks
Detection
Watch for these indicators of Gunra activity:
- Unusual outbound traffic from perimeter devices (potential data exfiltration staging)
- Admin tool usage (psexec, wmic, cobalt strike) from unusual sources
- Large-volume file access or staging prior to encryption
- Connections to known Gunra C2 infrastructure (IOCs in the full advisory)
Incident Response Preparedness
- Test backups now — Verify backup restoration works before you need it
- Maintain offline backups — Air-gapped or immutable backups are the critical last line of defense
- Have an IR retainer — Establish a relationship with an incident response firm before an incident occurs
- Practice tabletop exercises that include ransomware scenarios
The Broader Context
The Gunra advisory arrives amid a surge in ransomware activity targeting critical infrastructure in 2026. The joint US-South Korea nature of the advisory suggests Gunra has conducted significant operations against both nations' infrastructure, and reflects growing international cooperation in cybersecurity threat intelligence sharing.
For critical infrastructure operators, the message from law enforcement is clear: unpatched perimeter devices are the front door ransomware groups are walking through. The technical sophistication required for these attacks is lower than many defenders assume — the barrier is patching velocity, not attacker capability.
Sources
- The Record — FBI, South Korea Warn of Gunra Ransomware
- FBI Cyber Division Joint Advisory (August 2026)
- South Korea KISA (Korea Internet & Security Agency)