my timesThe Korea Times
  1. South Korea
  2. Law & Crime

Korea, US issue joint advisory on 'Gunra' ransomware attacks

Listen

Summary

Police and U.S. authorities on Tuesday released a joint advisory on Gunra ransomware attacks and urged domestic companies and institutions to tighten security. The KNPA said the guidance includes the latest attack methods and indicators of compromise. Gunra first appeared in 2025 and has evolved into ransomware-as-a-service targeting government, critical infrastructure and multiple sectors. Authorities said basic defenses such as restricted access, security patches and multi-factor authentication are key.


Key Facts

  • The KNPA said it distributed the advisory with U.S. agencies including the FBI and the National Security Agency.
  • The advisory says Gunra first appeared in 2025 and has developed into a ransomware-as-a-service operation.
  • The ransomware targets government and critical infrastructure, as well as finance, healthcare and manufacturing sectors.
  • Gunra gangs reportedly exploit system vulnerabilities, including weaknesses in security equipment, before deploying the ransomware.
  • The KNPA said it is investigating Gunra-related attacks and will keep improving its response with international cooperation.
By Yonhap
  • Published Aug 11, 2026 11:01 am KST
 gettyimagesbank

gettyimagesbank

Police on Tuesday called on domestic companies and institutions to strengthen their security against a ransomware variant named "Gunra," as they jointly released details of its latest attack methods with U.S. authorities.

The Korean National Police Agency (KNPA) said it has distributed a joint cybersecurity advisory regarding the Gunra ransomware with U.S. agencies, including the Federal Bureau of Investigation (FBI) and the National Security Agency.

Ransomware, a compound word of ransom and software, refers to malicious codes hackers use to encrypt or block access to data and demand money to restore access.

The advisory contains the latest attack techniques and indicators of compromise of the Gunra ransomware to help organizations defend networks from ransomware attacks, the KNPA said.

The Gunra ransomware variant first appeared in 2025 and recently evolved into a ransomware-as-a-service operation targeting government and critical infrastructure, as well as various sectors, including finance, healthcare and manufacturing, according to the advisory.

It said Gunra ransomware gangs breach critical infrastructure organizations by exploiting system vulnerabilities, including those in security equipment, before gaining access to their networks and deploying the ransomware. They employ a double-extortion model, encrypting data while threatening to publish exfiltrated data on a dedicated leak site or sell it if the ransom is not paid.

The KNPA said blocking the initial infiltration of ransomware attacks is the most effective response, advising companies and institutions to adhere to basic security protocols.

Specifically, they are urged to restrict external access to their networks, apply the latest security patches and strengthen account management by implementing multi-factor authentication, according to the police.

The KNPA also said it is currently investigating Gunra ransomware-related attacks and plans to continuously enhance response capabilities by cooperating with the international community.

Explore More

  • Q.

  • Q.

  • Q.