The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned on Monday. Monday’s report included evidence gleaned from several incidents handled by the FBI and South Korea’s police agency. Two weeks ago, researchers warned that some tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with Gunra as it targeted South Korean organizations. By January, Gunra moved to a ransomware-as-a-service model and the group was seen on cybercriminals forums actively recruiting new members. The advisory comes as industry groups warn that ransomware incidents continue to increase, particularly those targeting critical industrial organizations.