Patch Fortinet and Schneider Electric gear before anything else: that is the core advice in a joint U.S.-South Korea warning about Gunra, a Conti-derived ransomware operation now hitting critical infrastructure.
Healthcare, financial services, government facilities, and professional and nonprofit organizations are all in the crosshairs. Initial access comes through CVE-2025-24472, a Fortinet FortiOS and FortiProxy flaw, and CVE-2024-5559, a Schneider Electric PowerLogic P5 issue. From there the crew encrypts systems and steals data in a double extortion model.
Beyond patching, agencies recommend network segmentation, multifactor authentication, and tested offline backups so encrypted environments can be restored without paying. Refuse to pay and the stolen data lands on a leak site within five to seven days.
Since April 2025 the group has put 51 victims on Ransomware.Live, mostly in South Korea, Brazil, Spain, Thailand, and Hong Kong, and only three in Canada and the United States. The crew leans on phishing for delivery, runs negotiations from a WhatsApp-styled chat panel, and its locker can chew through files up to 9TB in a short window using stream ciphers such as Salsa20 or ChaCha20. A formal ransomware-as-a-service affiliate program opened on dark web forums in January 2026.
The advisory includes a full list of indicators of compromise and detection rules for defenders to review.
