← All stories
● Covered by 3 sources · 4 reportsHigh impact4 negative

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws, Linked to Lazarus Group

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Gunra ransomware exploits Fortinet and Schneider Electric vulnerabilities.
  • Targets include healthcare, financial, and government sectors globally.
  • Lazarus Group shares tools and infrastructure with Gunra.
  • Both groups exploit flaws in Korean financial security software.
  • Gunra uses a double extortion model, encrypting and exfiltrating data.

International Warning on Gunra Ransomware

Cybersecurity agencies from the U.S. and South Korea have issued warnings regarding the Gunra ransomware group. This group is actively targeting critical infrastructure organizations worldwide, including sectors such as healthcare, financial services, and government services.

Gunra, which emerged in April 2025, is a ransomware variant built using source code from the Conti ransomware that was leaked in 2022. It employs a double extortion model, combining data exfiltration with data encryption.

Exploited Vulnerabilities

The Gunra ransomware group gains initial access by exploiting security flaws in internet-facing appliances. Specifically, they leverage CVE-2024-55591 and CVE-2025-24472, which affect Fortinet FortiOS/FortiProxy software and Fortinet firewall products. Additionally, vulnerabilities in Schneider Electric PowerLogic P5 appliances (CVE-2024-5559) are being exploited.

These exploits allow Gunra actors to gain privileged access, steal and encrypt data, and then demand an extortion payment. Victims who do not pay within five to seven days may have their data published on a data leak site.

Lazarus Group Connection

South Korean security and intelligence agencies, alongside cybersecurity firm AhnLab, report that North Korea’s Lazarus Group is sharing cyberattack tools and infrastructure with the Gunra ransomware scheme. Both groups have run parallel campaigns against South Korean targets since 2025, differing primarily in their final objectives.

Both Lazarus and Gunra have exploited the same vulnerabilities in Korean financial security software products that are mandatory for users of Korean banking or government services. While Lazarus has focused on installing espionage backdoors in organizations, Gunra has used its access for data encryption and extortion.

Targeted Organizations and Evolution

Lazarus Group has installed espionage backdoors in at least 72 organizations in 2026 alone, including government agencies, cryptocurrency exchanges, and IT service providers. Gunra has listed 51 victims since its emergence, with most located in South Korea.

Initially focusing on Windows environments, Gunra actors introduced a Linux variant in mid-2025, expanding their operations to cross-platform campaigns. The group has also been observed attempting to communicate directly with management staff at victim companies to solicit ransom payments.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

US federal agencies and South Korea's National Policy Agency issued a joint advisory warning government and critical infrastructure organizations about Gunra ransomware attacks. Gunra, a Conti-derived ransomware, exploits vulnerabilities in Fortinet firewalls and VPN gateways, and has expanded operations with a ransomware-as-a-service platform and recruitment of initial access brokers.

Cybersecurity agencies from South Korea and the U.S. issued a warning about Gunra ransomware attacks targeting critical infrastructure sectors globally. The attacks exploit security vulnerabilities in Fortinet FortiOS/FortiProxy and Schneider Electric PowerLogic P5 appliances to gain initial access, then deploy ransomware and exfiltrate data. This development highlights the ongoing threat ransomware poses to essential services and the importance of patching known vulnerabilities.

The FBI and South Korea's government issued a joint cybersecurity advisory regarding the Gunra ransomware gang, which is exploiting vulnerabilities in Fortinet firewall products to breach critical infrastructure organizations. This group, which emerged in April 2025 and uses Conti ransomware source code, targets healthcare, financial, and government sectors globally, demanding ransoms exceeding $10 million.

North Korea's Lazarus Group is reportedly sharing cyberattack tools and infrastructure with ransomware criminals, specifically the Gunra ransomware scheme, to target South Korean organizations. This collaboration or shared access allows both groups to exploit the same vulnerabilities in mandatory Korean financial security software, with Lazarus focusing on espionage and Gunra on data encryption and extortion.