Skip to content

Gunra

Gunra is a Conti-derived ransomware family and ransomware-as-a-service operation first observed in 2025.

Profile source: Mallory opens in a new tab

Gunra

Family profile

Gunra is a Conti-derived ransomware family and ransomware-as-a-service operation first observed in 2025. It initially appeared in attacks against South Korean organizations and later expanded into a broader global extortion operation affecting sectors including healthcare, manufacturing, IT, pharmaceuticals, real estate, and other enterprise environments. Gunra has been associated with double-extortion activity in which operators steal data before encrypting systems and threaten publication through Tor-based leak infrastructure if victims do not pay.

Gunra supports both Windows and Linux environments, and reporting also indicates affiliate marketing that advertised broader cross-platform support. On Windows, Gunra encrypts files, appends a characteristic encrypted-file extension, and drops ransom notes in affected directories. It has been observed enumerating files and processes, collecting system information, deleting shadow copies, and using anti-analysis checks such as debugger detection. It also disables or interferes with backup and security controls to hinder recovery. On Linux, Gunra was developed into a compact ELF locker targeting enterprise servers and avoiding certain critical system directories to preserve system operability during extortion. Linux variants have also been reported modifying authentication, privilege, scheduled-task, and startup-related configurations to maintain access or facilitate post-compromise operations.

Gunra evolved from early Conti-based code into a more mature affiliate-driven platform with centralized management features for payload generation, negotiation, and branding. By early 2026 it had transitioned into a formal RaaS model, recruiting affiliates on criminal forums and enabling white-label use that could cause technically related attacks to appear under different names. Operators have been reported to participate directly in negotiations, indicating centralized oversight beyond simple payload leasing.

Gunra intrusions have been linked to multiple initial-access patterns. High-confidence reporting ties some South Korean incidents to exploitation of vulnerabilities in locally deployed financial security software through watering-hole attacks on compromised legitimate websites, as well as spearphishing. In those cases, Gunra activity overlapped technically with a separate espionage-focused intrusion cluster dubbed Operation Double Barrel, including shared exploit paths, tooling characteristics, infrastructure elements, and anti-forensic behavior. Assessments indicate Gunra and the espionage actor were likely distinct operators with different end goals, but may have shared tools, infrastructure, access, or collaborated in a limited manner. Some reporting specifically notes overlap with activity attributed to Lazarus, though definitive attribution of Gunra itself to a state actor is not established.

Gunra is primarily used for financially motivated extortion. Its operational model combines encryption, data theft, anti-forensic measures, and affiliate enablement, making it a notable emerging ransomware threat across both workstation and server environments.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Privilege Escalation

Operational record

5
Indicators
1
YARA rules
2
Ransom notes
2
Leak sites
1 available

Published indicators

Md5

4 total
  • 9a7c0adedc4c68760e49274700218507
  • 7dd26568049fac1b87f676ecfaac9ba0
  • ae6f61c0fc092233abf666643d88d0f3
  • f6664f4e77b7bcc59772cd359fdf271c

Ip

1 total
  • 86.54.28.216

Recent claims

Reported operators

Threat actors

1 named in public reporting
Lazarus

The technical report from cybersecurity firm AhnLab details how the state-sponsored North Korean group, widely tracked as Lazarus, and the Gunra ransomware scheme ran parallel campaigns against South Korean targets from 2025 through the first half of this year, differing only in their final objective.

MITRE ATT&CK

Gunra in ATT&CK

24 distinct techniques

Reporting

Research mentioning Gunra

Jul 30
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

South Korean authorities and AhnLab disclosed Operation Double Barrel, a campaign that targeted Korean citizens and businesses from 2025 through the first half of 2026 by exploiting vulnerabilities in Korean financial security software. The activity used watering hole and spear-phishing attacks to direct victims to malicious URLs, after which attackers deployed backdoors including Struggle (also tracked as SIGNBT 3.0) and Brandoor (COPPERHEDGE). Legitimate Korean websites in media, education, healthcare, and manufacturing were abused as part of the watering hole infrastructure, and investigators said the pattern also raised possible supply-chain concerns tied to a shared website development and management company. The same software flaws were also used in separate intrusions that delivered Gunra ransomware, leading to file encryption and data exfiltration. A joint cybersecurity advisory issued by South Korea's National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute said overlapping vulnerabilities, malware characteristics, SSH key fingerprints, and network infrastructure indicate possible limited collaboration or shared tooling between a state-sponsored threat actor and the Gunra ransomware group, although the relationship has not been confirmed definitively.

Jul 30
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Jul 30
Malware News

[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) - Malware Analysis - Malware Analysis, News and Indicators

Jul 30
Enki

합동 사이버 보안 권고문 기술 분석 보고서(워터링홀 공격) | 엔키화이트햇

Jul 29
Ahnlab Asec

[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) - ASEC

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.