U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks.

In a Monday joint advisory, they said the ransomware group uses a malware variant based on the Conti ransomware source code leaked in February 2022, in attacks targeting a wide range of industry sectors, from healthcare and public health to financial and government services.

"Gunra first emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti1 ransomware source code," the authoring agencies said.

"The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments with limited success."

The ransomware gang has been observed attacking Fortinet firewalls to gain a foothold on their targets' networks using exploits targeting two critical authentication vulnerabilities (CVE-2024-55591 and CVE-2025-24472) in FortiOS and FortiProxy software.