Md5
4 total9a7c0adedc4c68760e492747002185077dd26568049fac1b87f676ecfaac9ba0ae6f61c0fc092233abf666643d88d0f3f6664f4e77b7bcc59772cd359fdf271c
Gunra is a Conti-derived ransomware family and ransomware-as-a-service operation first observed in 2025.
Profile source: Mallory opens in a new tabGunra
Gunra is a Conti-derived ransomware family and ransomware-as-a-service operation first observed in 2025. It initially appeared in attacks against South Korean organizations and later expanded into a broader global extortion operation affecting sectors including healthcare, manufacturing, IT, pharmaceuticals, real estate, and other enterprise environments. Gunra has been associated with double-extortion activity in which operators steal data before encrypting systems and threaten publication through Tor-based leak infrastructure if victims do not pay.
Gunra supports both Windows and Linux environments, and reporting also indicates affiliate marketing that advertised broader cross-platform support. On Windows, Gunra encrypts files, appends a characteristic encrypted-file extension, and drops ransom notes in affected directories. It has been observed enumerating files and processes, collecting system information, deleting shadow copies, and using anti-analysis checks such as debugger detection. It also disables or interferes with backup and security controls to hinder recovery. On Linux, Gunra was developed into a compact ELF locker targeting enterprise servers and avoiding certain critical system directories to preserve system operability during extortion. Linux variants have also been reported modifying authentication, privilege, scheduled-task, and startup-related configurations to maintain access or facilitate post-compromise operations.
Gunra evolved from early Conti-based code into a more mature affiliate-driven platform with centralized management features for payload generation, negotiation, and branding. By early 2026 it had transitioned into a formal RaaS model, recruiting affiliates on criminal forums and enabling white-label use that could cause technically related attacks to appear under different names. Operators have been reported to participate directly in negotiations, indicating centralized oversight beyond simple payload leasing.
Gunra intrusions have been linked to multiple initial-access patterns. High-confidence reporting ties some South Korean incidents to exploitation of vulnerabilities in locally deployed financial security software through watering-hole attacks on compromised legitimate websites, as well as spearphishing. In those cases, Gunra activity overlapped technically with a separate espionage-focused intrusion cluster dubbed Operation Double Barrel, including shared exploit paths, tooling characteristics, infrastructure elements, and anti-forensic behavior. Assessments indicate Gunra and the espionage actor were likely distinct operators with different end goals, but may have shared tools, infrastructure, access, or collaborated in a limited manner. Some reporting specifically notes overlap with activity attributed to Lazarus, though definitive attribution of Gunra itself to a state actor is not established.
Gunra is primarily used for financially motivated extortion. Its operational model combines encryption, data theft, anti-forensic measures, and affiliate enablement, making it a notable emerging ransomware threat across both workstation and server environments.
9a7c0adedc4c68760e492747002185077dd26568049fac1b87f676ecfaac9ba0ae6f61c0fc092233abf666643d88d0f3f6664f4e77b7bcc59772cd359fdf271c86.54.28.216Reported operators
The technical report from cybersecurity firm AhnLab details how the state-sponsored North Korean group, widely tracked as Lazarus, and the Gunra ransomware scheme ran parallel campaigns against South Korean targets from 2025 through the first half of this year, differing only in their final objective.
MITRE ATT&CK
Reporting
South Korean authorities and AhnLab disclosed Operation Double Barrel, a campaign that targeted Korean citizens and businesses from 2025 through the first half of 2026 by exploiting vulnerabilities in Korean financial security software. The activity used watering hole and spear-phishing attacks to direct victims to malicious URLs, after which attackers deployed backdoors including Struggle (also tracked as SIGNBT 3.0) and Brandoor (COPPERHEDGE). Legitimate Korean websites in media, education, healthcare, and manufacturing were abused as part of the watering hole infrastructure, and investigators said the pattern also raised possible supply-chain concerns tied to a shared website development and management company. The same software flaws were also used in separate intrusions that delivered Gunra ransomware, leading to file encryption and data exfiltration. A joint cybersecurity advisory issued by South Korea's National Intelligence Service, National Police Agency, Korea Internet & Security Agency, and Financial Security Institute said overlapping vulnerabilities, malware characteristics, SSH key fingerprints, and network infrastructure indicate possible limited collaboration or shared tooling between a state-sponsored threat actor and the Gunra ransomware group, although the relationship has not been confirmed definitively.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.