US, South Korea Warn of Growing Gunra Ransomware Threat
U.S. and South Korean authorities warn about the growing Gunra ransomware threat as the operation expands its capabilities and affiliate network. The post US, South Korea Warn of Growing Gunra Ransomware Threat appeared first on TechRepublic .
The U.S. and South Korean authorities have issued warnings regarding the expanding threat posed by Gunra ransomware. This cyber threat has progressed from a localized issue in South Korea to a significant concern on an international scale. Gunra initially emerged in April 2025 after attacks targeted five South Korean organizations.
The ransomware operation started with ransomware based on leaked Conti source code, but soon evolved into a ransomware-as-a-service model, allowing affiliates to utilize the group's malware and infrastructure for attacks. As of March 9, 2026, the security firm S2W identified 32 organizations affected by Gunra activity. The use of an affiliate model enables ransomware operators to expand their operations without personally conducting every intrusion.
Gunra is capable of targeting both Windows and Linux systems, broadening the range of potential victims. Moreover, Gunra employs double-extortion tactics, where attackers steal data before encrypting systems, potentially exposing sensitive information. The rapid development of Gunra highlights how quickly ransomware groups can mature once they establish their own tooling and recruit affiliates.
Defenders should focus on essential measures, such as reducing exposed access, strengthening authentication, limiting lateral movement, and safeguarding critical systems for recovery.
Written by urgent.news from TechRepublic's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.