# Gunra

Type: Company

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/gunra
Canonical HTML page: https://getcyberbrief.com/entity/gunra

## Timeline

- **2026-08-11**: Joint US-South Korea advisory issued — CISA and South Korean intelligence agencies release a cybersecurity advisory detailing Gunra's exploitation of Fortinet and Schneider Electric flaws.
- **2026-01**: Formal RaaS affiliate program launched — Gunra operators announce a ransomware-as-a-service program on dark web forums, providing affiliates with a management panel and tools.
- **2025-04**: Gunra ransomware emerges — The Gunra ransomware group is first observed in the wild, targeting global organizations with double extortion tactics.

## Recent coverage (1 stories)

### Gunra Ransomware: 51 Victims After Exploiting 2 Fortinet & Schneider Flaws
2026-08-12 00:31:31 · Sentiment: Strongly negative · Impact: 8/10 · Sources: 3

A joint US-South Korea advisory reveals Gunra ransomware has hit 51 organizations by weaponizing CVE-2024-5559 in Schneider Electric gear and CVE-2025-24472 in Fortinet products. The group uses double extortion, phishing, and advanced encryption, having launched a formal RaaS program in January 2026.
Full story: https://getcyberbrief.com/story/gunra-ransomware-exploits-fortinet-schneider-flaws-51-victims

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.