U.S. federal agencies and South Korea's National Policy Agency have warned government and critical infrastructure organizations worldwide to harden systems against Gunra ransomware, according to BleepingComputer. The report says the warning came in a Monday joint advisory focused on a ransomware group using malware derived from the leaked Conti source code. The advisory describes Gunra as a double-extortion ransomware variant that first appeared in April 2025, BleepingComputer reports. It says the malware is based on Conti ransomware source code that leaked in February 2022, a lineage that matters because leaked ransomware code can be reused, modified, and commercialized by later criminal groups. According to BleepingComputer’s summary of the advisory, Gunra has targeted a broad set of sectors, including healthcare and public health, financial services, and government services. The warning is directed not only at government agencies but also at critical infrastructure operators, suggesting the agencies view the campaign as relevant to organizations with high operational and public-service exposure. The advisory identifies multiple initial-access paths. BleepingComputer reports that Gunra actors have attacked Fortinet firewalls by exploiting two critical authentication vulnerabilities, CVE-2024-55591 and CVE-2025-24472, affecting FortiOS and FortiProxy software. The group has also exploited credential-exposure and Secure Shell access-control weaknesses in internet-facing virtual private network gateways to reach victim systems remotely. The group’s platform coverage has also broadened. While Gunra’s attacks initially focused on Windows environments, the advisory says the operators moved into cross-platform campaigns after adding a Linux variant in mid-2025, according to BleepingComputer. That shift raises the defensive scope for organizations running mixed Windows and Linux estates, particularly where Linux systems support network services, infrastructure, or production workloads. BleepingComputer reports that Gunra’s business model has matured as well. Since January 2026, the group has launched a formal ransomware-as-a-service affiliate program on dark web forums, offering affiliates a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured documentation, according to the advisory. The FBI also observed the group using new branding aliases, notably Golden Community, as part of that expansion. The advisory says Gunra has tried to recruit penetration testers and ethical hackers as initial access brokers, offering a share of ransom proceeds in exchange for enterprise network access, BleepingComputer reports. It also says the FBI observed Gunra actors attempting to email management staff at victim companies directly to solicit ransom payments, with limited success. The recommended defensive measures are conventional but urgent: patch known exploited vulnerabilities in internet-facing systems quickly, segment networks to limit lateral movement, and maintain offline backups. BleepingComputer also notes that the joint alert follows a separate advisory from South Korean cybersecurity firm AhnLab and multiple South Korean government agencies that described links between Gunra and Lazarus Group, the North Korean state-backed hacking group. Who benefits: Security teams benefit from specific indicators of how the group is gaining access and expanding operations. Organizations with current asset inventories and disciplined patching processes are better positioned to act on the advisory quickly. Who's exposed: Government agencies, critical infrastructure operators, healthcare organizations, financial services firms, and other enterprises with internet-facing Fortinet or VPN systems are the clearest exposed groups in the report. Mixed Windows and Linux environments also face broader scope after the reported Linux variant.