Gunra ransomware, built on Conti code, hits critical infrastructure
The Conti source code leaked in 2022 keeps spawning operational variants, but Gunra's Linux variant has a cryptographic weakness defenders can exploit to recover files.
TL;DR
The FBI and South Korea's National Policy Agency issued a joint advisory Monday on Gunra ransomware, which exploits Fortinet firewall vulnerabilities CVE-2024-55591 and CVE-2025-24472 to breach critical infrastructure organizations globally. Built from Conti source code leaked in 2022, Gunra emerged in April 2025 and has since shifted to a ransomware-as-a-service model under the alias "Golden Community." Ransom demands typically exceed $10 million. The advisory notes a cryptographic weakness in Gunra's Linux variant: defenders can reconstruct encryption keys from file timestamps and recover files without paying.
The joint advisory from the FBI and South Korea's National Policy Agency confirms what the Conti leak foretold: source code that enters the wild doesn't expire. Gunra, which surfaced in April 2025, is built directly on the Conti codebase dumped in 2022, and it's now breaching healthcare, financial services, and government targets through two Fortinet firewall vulnerabilities, CVE-2024-55591 and CVE-2025-24472, that CISA had already flagged.
The lineage gets more interesting. In July, South Korean agencies and AhnLab published research showing that tools and infrastructure from North Korea's Lazarus Group were shared with Gunra operators as they ran parallel campaigns against South Korean targets. Same exploits, different endgames: Lazarus for espionage, Gunra for extortion. Since January, Gunra has operated as a ransomware-as-a-service outfit, rebranding as "Golden Community" and actively recruiting initial access brokers on cybercriminal forums.
For defenders, the advisory contains one immediately useful detail: as of March, researchers found that Gunra's Linux variant has a cryptographic flaw. Encryption keys can be reconstructed from file timestamps, meaning files can be recovered without paying. That's the kind of operational note that makes a joint advisory worth reading beyond the IOCs. Ransom demands, in most cases handled by the FBI and South Korean police, exceeded $10 million with five-to-seven-day payment windows, though the FBI noted that direct email solicitation of victim management had "limited success."
Dragos counted four Gunra-attributed attacks on industrial organizations in Q2 2026, down from eight in Q1, against a backdrop of 1,140 total ransomware incidents affecting industrial targets, a 12% quarterly increase.
Published ·Deep Fathom