started · updated
DeadLock and Gunra ransomware pose growing threats to critical infrastructure
Cybersecurity authorities and researchers have identified two significant ransomware threats: DeadLock and Gunra.
DeadLock ransomware utilizes a decentralized infrastructure to resist takedowns. According to Microsoft Threat Intelligence, the group uses the Polygon blockchain to store configuration data and host leak site content via smart contracts. This allows operators to rotate proxy addresses without modifying victim-facing applications. The group also employs the Session messaging network for encrypted communications and Wasabi cloud services for hosting stolen data. DeadLock uses a hybrid encryption scheme involving Curve25519 and XChaCha20, and has claimed approximately 96 victims across sectors such as IT, manufacturing, and transportation.
Separately, the FBI, CISA, and South Korea’s National Police Agency issued a joint advisory regarding Gunra ransomware. Gunra, which operates as a ransomware-as-a-service (RaaS) model, targets critical infrastructure including healthcare, finance, and government sectors. The group gains initial access by exploiting vulnerabilities in internet-facing Fortinet devices (CVE-2024-55591 and CVE-2025-24472). Gunra employs double extortion tactics, stealing sensitive data before encrypting systems and demanding ransoms that can exceed $10 million. The group has been observed targeting organizations across the Americas, Europe, the Middle East, Africa, and Asia-Pacific.
Entities
Accenture · CISA · Dragos · FBI · Fortinet · Gunra · Microsoft · Polygon
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 4 SOURCES] Gunra exploits Fortinet vulnerabilities CVE-2024-55591 and CVE-2025-24472 for initial access. cyberinsider.com · totalsecurity.com.br · itnerd.blog · www.globalsecuritymag.com
- [● 4 SOURCES] DeadLock ransomware uses the Polygon blockchain to store configuration data and leak site posts. nationalcybersecurity.com · ipaddisti.it · www.it-boltwise.de · thehackernews.com
- [● 5 SOURCES] Gunra ransomware targets critical infrastructure in healthcare, finance, and government sectors. cyberinsider.com · totalsecurity.com.br · itnerd.blog · www.executivegov.com · www.globalsecuritymag.com
- [○ 1 SOURCE] DeadLock has claimed 96 victims as of early 2026. thehackernews.com
- [○ 1 SOURCE] DeadLock uses the Session network for encrypted communications and Wasabi cloud service for stolen files. nationalcybersecurity.com
- [● 2 SOURCES] Gunra operates as a ransomware-as-a-service (RaaS) program. cyberinsider.com · www.executivegov.com
- [● 2 SOURCES] Gunra has been known to demand ransom amounts exceeding $10 million. cyberinsider.com · www.globalsecuritymag.com
- [● 2 SOURCES] DeadLock employs a hybrid cryptographic design using Curve25519 and XChaCha20. ipaddisti.it · thehackernews.com