
US-South Korea Joint Advisory Warns of Gunra Ransomware Targeting Critical Infrastructure via Industrial Control Flaws
A joint advisory from CISA, FBI, and South Korea’s NPA highlights the rise of Gunra, a Conti-derived RaaS group exploiting Fortinet and Schneider Electric vulnerabilities to target global critical sectors.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- CISA / FBI / South Korea National Police Agency (NPA)
- Read Time:
- 5 min
Executive Summary
On August 10-11, 2026, a joint cybersecurity advisory (AA26-222A) was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and South Korea’s National Police Agency (NPA) regarding the escalating threat of the Gunra ransomware group. Gunra, which emerged in early 2025, has rapidly evolved into a sophisticated Ransomware-as-a-Service (RaaS) operation. The group is currently targeting critical infrastructure sectors, including healthcare, financial services, and government facilities, utilizing a double-extortion model that combines data encryption with the threat of leaking sensitive information on a dedicated leak site (DLS). Recent activity indicates a strategic shift toward exploiting vulnerabilities in industrial control systems (ICS) and edge networking devices to gain initial access.
Threat Analysis
Gunra represents a significant evolution in the ransomware landscape, leveraging leaked source code from the defunct Conti ransomware gang to build a robust and evasive encryption engine. According to The Hacker News, the group has moved beyond simple phishing, increasingly focusing on the exploitation of unpatched vulnerabilities in enterprise and industrial hardware. The group’s double-extortion tactics are designed to maximize pressure; they not only paralyze operations but also exfiltrate proprietary technical assets, including engineering documentation and system configurations. Recent victims include 3Pro TV in Seoul, where over 460,000 records were exposed, and the City of Coweta, which suffered a system-wide disruption earlier this month.
Technical Details
The Gunra group is notably exploiting specific vulnerabilities in Fortinet and Schneider Electric products to bypass perimeter defenses. Intelligence suggests the actors are targeting known flaws in edge gateways to pivot into internal networks. Once inside, they deploy a variant of the Conti-based locker that features advanced anti-analysis and anti-sandbox routines. The group has also been observed using 'EDR kill' techniques, a trend highlighted in recent Infosecurity Magazine reports, where the ransomware payload includes modules to systematically disable antivirus and endpoint detection tools before beginning the encryption process. Lateral movement is typically achieved through the abuse of administrative credentials harvested via memory scraping tools like Mimikatz.
Attribution Assessment
Intelligence agencies have high confidence that Gunra is a successor to former Conti affiliates, likely operating out of Eastern Europe. The group’s commercialized platform actively recruits experienced penetration testers and 'ethical' hackers to refine their attack chains. While the group operates as a RaaS, the core developers maintain strict control over the DLS and negotiation portals. The recent joint advisory from BleepingComputer notes that the group’s TTPs (Tactics, Techniques, and Procedures) closely mirror those of the 'Storm-1175' actor, though Gunra remains a distinct entity focused on high-value industrial targets.
Implications
The targeting of Schneider Electric and Fortinet flaws indicates a dangerous focus on Operational Technology (OT). A successful breach in these environments can lead to physical safety risks and long-term economic disruption. The recent disruption of Ceva Logistics operations on August 12, 2026, underscores the fragility of global supply chains when faced with targeted ransomware campaigns. As Gunra continues to refine its AI-assisted targeting and EDR-evasion capabilities, the window for detection and containment is narrowing for defenders.
Recommendations
Encrygma recommends that all organizations, particularly those in critical infrastructure, prioritize the following: 1) Immediate patching of all Fortinet and Schneider Electric edge devices; 2) Implementation of strict network segmentation between IT and OT environments; 3) Deployment of phishing-resistant Multi-Factor Authentication (MFA) across all administrative portals; and 4) Regular auditing of RMM (Remote Monitoring and Management) tools to detect unauthorized administrative access. Organizations should also review CISA’s #StopRansomware guide for specific Gunra IOCs.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Gunra and Medusa Ransomware Groups Intensify Double-Extortion Campaigns Against Critical Infrastructure

Ransomware Surge: Over 1,000 Organizations Compromised in August 2026 Amidst Escalating Gang Conflicts

