{
  "id": 575339,
  "title": "Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure",
  "url": "https://urgent.news/2026/08/11/feds-warn-gunra-ransomware-is-exploiting-known-bugs-to-hit-critical",
  "topic": "world",
  "section": "World",
  "published": "2026-08-11T14:36:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/cyber-crime/2026/08/11/feds-warn-gunra-ransomware-is-exploiting-known-bugs-to-hit-critical-infrastructure/5286263"
  },
  "original_language": "en",
  "account": "Cybersecurity agencies in the United States have issued a warning to critical infrastructure operators about their internet-facing systems being vulnerable to Gunra ransomware. This ransomware variant, which first emerged in 2025, exploits known vulnerabilities in Fortinet's FortiOS and FortiProxy to gain unauthorized access to networks. Gunra has been observed targeting various sectors, including healthcare, financial services, government, and professional services, among others.\n\nThe ransomware's operators use a double-extortion tactic, where they first steal sensitive data and then encrypt critical systems. They demand payment for a decryption key and a promise not to publish the stolen information. The negotiation process occurs on a Tor-based portal, leaving potential victims with a five to seven-day window to comply before the data is published online.\n\nExperts attribute the persistence of Gunra to its ability to adapt and exploit new vulnerabilities. Trend Micro first identified the ransomware in April 2025, initially targeting Windows systems but later discovering a Linux version with enhanced capabilities. This new version can execute up to 100 encryption threads simultaneously, support partial encryption of individual files, and store RSA-encrypted keys in separate files for added complexity.\n\nThe Federal Bureau of Investigation, the National Security Agency, the Secret Service, and allied agencies from the United States and South Korea are warning organizations to patch their internet-facing systems promptly, secure VPN gateways and Remote Desktop Protocol (RDP) access with multi-factor authentication, segment their networks, and maintain offline, immutable backups. These measures can help mitigate the risks associated with Gunra ransomware and protect critical infrastructure from potential disruptions.",
  "summary": "Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure",
        "url": "https://urgent.news/2026/08/11/feds-warn-gunra-ransomware-is-exploiting-known-bugs-to-hit-critical-577019",
        "published": "2026-08-11T14:36:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}