Md5
4 total9a7c0adedc4c68760e492747002185077dd26568049fac1b87f676ecfaac9ba0ae6f61c0fc092233abf666643d88d0f3f6664f4e77b7bcc59772cd359fdf271c
Gunra is a financially motivated, Conti-derived ransomware family that emerged in April 2025 and evolved into a ransomware-as-a-service operation by early 2026.
Profile source: Mallory opens in a new tabGunra
Gunra is a financially motivated, Conti-derived ransomware family that emerged in April 2025 and evolved into a ransomware-as-a-service operation by early 2026. Also known as Golden Community, it provides affiliates with ransomware builders, payloads, management infrastructure, and documentation. Gunra conducts double-extortion attacks: affiliates exfiltrate sensitive business data, encrypt victim systems, and threaten to publish or sell stolen data if payment is not made.
Gunra has targeted government, critical infrastructure, healthcare, financial services, manufacturing, transportation, utilities, and other organizations worldwide. Initial access has been observed through exploitation of known vulnerabilities in internet-facing VPN, firewall, and remote-access appliances, including FortiOS and FortiProxy authentication-bypass vulnerabilities CVE-2024-55591 and CVE-2025-24472. Observed post-compromise activity includes creation or abuse of privileged accounts, theft of credentials and session material, multifactor-authentication bypass through VDI authentication tampering, SMB-based lateral movement using Impacket, reconnaissance, collection of cloud-hosted enterprise data, log clearing, and deletion of backups and recovery data.
Gunra supports Windows and Linux environments. Its Windows encryption implementation uses ChaCha20 with RSA-4096 key protection and parallel processing. Linux builds support multithreaded and partial encryption; reported weaknesses in some Linux variants' random-number generation may permit recovery in affected cases. Gunra operators use Tor-based negotiation and leak infrastructure, encrypted messaging, and cloud file-sharing services in support of extortion and data theft.
9a7c0adedc4c68760e492747002185077dd26568049fac1b87f676ecfaac9ba0ae6f61c0fc092233abf666643d88d0f3f6664f4e77b7bcc59772cd359fdf271c86.54.28.216Reported operators
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. "Gunra first emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti1 ransomware source code."
Exploited software
MITRE ATT&CK
Reporting
South Korean authorities and AhnLab disclosed Operation Double Barrel, a campaign that targeted Korean citizens and businesses from 2025 through the first half of 2026 by exploiting vulnerabilities in Korean financial security software. The activity used watering hole and spear-phishing attacks to direct victims to malicious URLs, after which attackers deployed backdoors including Struggle (also tracked as SIGNBT 3.0) and Brandoor (COPPERHEDGE). Legitimate Korean websites in media, education, healthcare, and manufacturing were abused as part of the watering hole infrastructure, and investigators said the pattern also raised possible supply-chain concerns tied to a shared website development and management company. The same software flaws were also used in separate intrusions that delivered Gunra ransomware, leading to file encryption and data exfiltration. A joint cybersecurity advisory issued by South Korea's National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute said overlapping vulnerabilities, malware characteristics, SSH key fingerprints, and network infrastructure indicate possible limited collaboration or shared tooling between a state-sponsored threat actor and the Gunra ransomware group, although the relationship has not been confirmed definitively.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.