Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Gunra

Gunra

TLP:CLEAR
Family

AI Analysis

No AI analysis yet.

Description

Gunra is a highly aggressive ransomware family that first emerged in April 2025, operating as a Ransomware-as-a-Service (RaaS). It is built upon the leaked source code of the notorious Conti ransomware. As a double-extortion threat, Gunra not only encrypts the victim's data but also exfiltrates sensitive business information. The threat actors then threaten to publish this stolen data on their Tor-hosted leak sites if the ransom is not paid within a strict 5-day deadline. Gunra has a global footprint, heavily targeting critical infrastructure, healthcare, pharmaceuticals, manufacturing and real estate across both Windows and Linux environments. The name of the ransomware is derived from the malicious executable process it spawns upon infection, typically named gunraransome.exe. It systematically deletes all Volume Shadow Copies via Windows Management Instrumentation (WMI) to prevent victims from easily restoring their files. Once Gunra has secured its foothold and terminated interfering processes, it encrypts the victim's files using a combination of ChaCha20 and RSA-4096 encryption, notably featuring "step-skip" partial encryption to maximize speed. The encrypted files are easily identifiable because the malware appends the .ENCRT extension to their original filenames. In every directory where files have been encrypted, the malware drops a ransom note named R3ADM3.txt. This note informs the victim of the double extortion and provides instructions on how to contact the attackers. Victims are directed to a negotiation portal hosted on the Tor network to initiate communication, utilizing .onion addresses such as [http://gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad.onion/]

Details

Type
Unknown
Platforms
Windows
Confidence
80%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.