Skip to content

Gunra

Gunra is a financially motivated, Conti-derived ransomware family that emerged in April 2025 and evolved into a ransomware-as-a-service operation by early 2026.

Profile source: Mallory opens in a new tab

Gunra

Family profile

Gunra is a financially motivated, Conti-derived ransomware family that emerged in April 2025 and evolved into a ransomware-as-a-service operation by early 2026. Also known as Golden Community, it provides affiliates with ransomware builders, payloads, management infrastructure, and documentation. Gunra conducts double-extortion attacks: affiliates exfiltrate sensitive business data, encrypt victim systems, and threaten to publish or sell stolen data if payment is not made.

Gunra has targeted government, critical infrastructure, healthcare, financial services, manufacturing, transportation, utilities, and other organizations worldwide. Initial access has been observed through exploitation of known vulnerabilities in internet-facing VPN, firewall, and remote-access appliances, including FortiOS and FortiProxy authentication-bypass vulnerabilities CVE-2024-55591 and CVE-2025-24472. Observed post-compromise activity includes creation or abuse of privileged accounts, theft of credentials and session material, multifactor-authentication bypass through VDI authentication tampering, SMB-based lateral movement using Impacket, reconnaissance, collection of cloud-hosted enterprise data, log clearing, and deletion of backups and recovery data.

Gunra supports Windows and Linux environments. Its Windows encryption implementation uses ChaCha20 with RSA-4096 key protection and parallel processing. Linux builds support multithreaded and partial encryption; reported weaknesses in some Linux variants' random-number generation may permit recovery in affected cases. Gunra operators use Tor-based negotiation and leak infrastructure, encrypted messaging, and cloud file-sharing services in support of extortion and data theft.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking

Operational record

5
Indicators
1
YARA rules
2
Ransom notes
2
Leak sites
1 available

Published indicators

Md5

4 total
  • 9a7c0adedc4c68760e49274700218507
  • 7dd26568049fac1b87f676ecfaac9ba0
  • ae6f61c0fc092233abf666643d88d0f3
  • f6664f4e77b7bcc59772cd359fdf271c

Ip

1 total
  • 86.54.28.216

Recent claims

Reported operators

Threat actors

1 named in public reporting
Lazarus

U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. "Gunra first emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti1 ransomware source code."

Exploited software

Vulnerabilities linked to Gunra

3 CVEs

MITRE ATT&CK

Gunra in ATT&CK

58 distinct techniques

Techniques

58 techniques
T1530 Data from Cloud Storage T1567.002 Exfiltration to Cloud Storage T1090.003 Multi-hop Proxy T1486 Data Encrypted for Impact T1566.003 Spearphishing via Service T1041 Exfiltration Over C2 Channel T1190 Exploit Public-Facing Application T1657 Financial Theft T1537 Transfer Data to Cloud Account T1133 External Remote Services T1567 Exfiltration Over Web Service T1485 Data Destruction T1111 Multi-Factor Authentication Interception T1556 Modify Authentication Process T1574 Hijack Execution Flow T1539 Steal Web Session Cookie T1078 Valid Accounts T1649 Steal or Forge Authentication Certificates T1003 OS Credential Dumping T1078.001 Default Accounts T1083 File and Directory Discovery T1070 Indicator Removal T1021.002 SMB/Windows Admin Shares T1059 Command and Scripting Interpreter T1497 Virtualization/Sandbox Evasion T1570 Lateral Tool Transfer T1021.004 SSH T1490 Inhibit System Recovery T1021 Remote Services T1070.001 Clear Windows Event Logs T1557 Adversary-in-the-Middle T1560 Archive Collected Data T1566 Phishing T1598 Phishing for Information T1136 Create Account T1583 Acquire Infrastructure T1585.001 Social Media Accounts T1106 Native API T1622 Debugger Evasion T1005 Data from Local System T1679 Selective Exclusion T1189 Drive-by Compromise T1203 Exploitation for Client Execution T1195 Supply Chain Compromise T1082 System Information Discovery T1562 Impair Defenses T1070.004 File Deletion T1057 Process Discovery T1020 Automated Exfiltration T1027 Obfuscated Files or Information T1047 Windows Management Instrumentation T1037 Boot or Logon Initialization Scripts T1059.004 Unix Shell T1491.001 Internal Defacement T1548 Abuse Elevation Control Mechanism T1053.003 Cron T1070.002 Clear Linux or Mac System Logs T1556.003 Pluggable Authentication Modules

Reporting

Research mentioning Gunra

Jul 30
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

South Korean authorities and AhnLab disclosed Operation Double Barrel, a campaign that targeted Korean citizens and businesses from 2025 through the first half of 2026 by exploiting vulnerabilities in Korean financial security software. The activity used watering hole and spear-phishing attacks to direct victims to malicious URLs, after which attackers deployed backdoors including Struggle (also tracked as SIGNBT 3.0) and Brandoor (COPPERHEDGE). Legitimate Korean websites in media, education, healthcare, and manufacturing were abused as part of the watering hole infrastructure, and investigators said the pattern also raised possible supply-chain concerns tied to a shared website development and management company. The same software flaws were also used in separate intrusions that delivered Gunra ransomware, leading to file encryption and data exfiltration. A joint cybersecurity advisory issued by South Korea's National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute said overlapping vulnerabilities, malware characteristics, SSH key fingerprints, and network infrastructure indicate possible limited collaboration or shared tooling between a state-sponsored threat actor and the Gunra ransomware group, although the relationship has not been confirmed definitively.

Jul 30
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Jul 30
Malware News

[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) - Malware Analysis - Malware Analysis, News and Indicators

Jul 30
Enki

합동 사이버 보안 권고문 기술 분석 보고서(워터링홀 공격) | 엔키화이트햇

Jul 29
Ahnlab Asec

[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) - ASEC

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.