The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.

August 11, 2026

A burgeoning ransomware-as-a-service (RaaS) operation is using known exploited vulnerabilities in campaigns against critical infrastructure and government organizations around the globe.

US and South Korean government agencies issued a joint cybersecurity alert on Monday regarding Gunra, a ransomware gang that first emerged in the spring of 2025. Gunra's ransomware is "a sophisticated double-extortion ransomware variant" based on the leaked source code of the now-defunct Conti gang, according to the advisory.

Initially, Gunra operators focused on Windows environments before developing a Linux variant and further expanding operations this year. "As of early 2026, Gunra expanded its operations through a structured RaaS affiliate program advertised on Dark Web forums to financially motivated cybercriminals," the advisory states.