< Back to all clusters
[TECHNOLOGY] · United States, South Korea, Italy, Spain, Poland · 11 sources

started · updated

DeadLock and Gunra ransomware pose growing threats to critical infrastructure

Cybersecurity authorities and researchers have identified two significant ransomware threats: DeadLock and Gunra.

DeadLock ransomware utilizes a decentralized infrastructure to resist takedowns. According to Microsoft Threat Intelligence, the group uses the Polygon blockchain to store configuration data and host leak site content via smart contracts. This allows operators to rotate proxy addresses without modifying victim-facing applications. The group also employs the Session messaging network for encrypted communications and Wasabi cloud services for hosting stolen data. DeadLock uses a hybrid encryption scheme involving Curve25519 and XChaCha20, and has claimed approximately 96 victims across sectors such as IT, manufacturing, and transportation.

Separately, the FBI, CISA, and South Korea’s National Police Agency issued a joint advisory regarding Gunra ransomware. Gunra, which operates as a ransomware-as-a-service (RaaS) model, targets critical infrastructure including healthcare, finance, and government sectors. The group gains initial access by exploiting vulnerabilities in internet-facing Fortinet devices (CVE-2024-55591 and CVE-2025-24472). Gunra employs double extortion tactics, stealing sensitive data before encrypting systems and demanding ransoms that can exceed $10 million. The group has been observed targeting organizations across the Americas, Europe, the Middle East, Africa, and Asia-Pacific.

Entities

Accenture · CISA · Dragos · FBI · Fortinet · Gunra · Microsoft · Polygon

Claims

What the coverage asserts, and how well corroborated each claim is across sources.