Updated
Updated · The Hacker News · Aug 11
U.S., South Korea Warn Gunra Hit 51 Victims via 2 Fortinet, Schneider Flaws
Updated
Updated · The Hacker News · Aug 11

U.S., South Korea Warn Gunra Hit 51 Victims via 2 Fortinet, Schneider Flaws

3 articles · Updated · The Hacker News · Aug 11

Summary

  • 51 victims have been listed since April 2025, as U.S. and South Korean agencies said Gunra is targeting critical infrastructure, including healthcare, finance, government and nonprofit organizations worldwide.
  • Two exploited flaws—Schneider Electric PowerLogic P5 CVE-2024-5559 and Fortinet FortiOS/FortiProxy CVE-2025-24472—have given attackers initial access before double-extortion attacks that encrypt data and threaten leaks within five to seven days.
  • Gunra’s operators use phishing, SMB-based lateral movement and credential dumping, and in one South Korean case hijacked VDI sessions and tampered with MFA processing to force authentication with a designated one-time password.
  • The Conti-derived group launched a formal RaaS affiliate program in January 2026, rebranded at times as Golden Community, and has recruited penetration testers and ethical hackers as initial access brokers for ransom shares.
  • South Korean researchers also linked some Gunra intrusions to malware and infrastructure overlaps with Lazarus-linked campaigns, underscoring concerns about limited collaboration between ransomware crews and state-backed actors.

Insights

Could the shared digital footprints between Gunra and North Korea's Lazarus Group expose a terrifying new alliance in global cyber extortion?
If patching your firewall cannot stop the Gunra gang, what hidden backdoors are already lurking inside your critical infrastructure?
With executives receiving direct multi-million dollar ransom emails, how can organizations survive this ruthless new era of double-extortion ransomware?