Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Gunra

162
Global rank
153 infographic chevron month
Month rank
184 infographic chevron week
Week rank

Gunra ransomware, a financially motivated threat actor that emerged in April 2025, deploys double-extortion tactics to encrypt victims' data and threaten leaks of exfiltrated information, primarily targeting Windows and Linux systems across healthcare, manufacturing, and other sectors worldwide.

Ransomware
Type
Unknown
Origin
1 April, 2025
First seen
26 August, 2026
Last seen
Also known as
Conti

How to analyze Gunra with ANY.RUN

Type
Unknown
Origin
1 April, 2025
First seen
26 August, 2026
Last seen

IOCs

IP addresses
151.101.130.49
185.125.190.56
185.125.190.101
185.125.190.57
91.189.91.98
185.125.190.99
23.52.181.141
48.192.1.64
48.209.133.15
57.153.246.3
74.178.76.128
23.216.77.36
135.233.95.135
92.123.104.52
48.209.138.168
23.52.181.212
172.211.123.250
2.23.246.101
23.11.41.157
20.190.160.22
Hashes
5677dfad26045e271272bc98be2fd24e2f6d13737850ab1d9857fd58de05e9f9
854e5f77f788bbbe6e224195e115c749172cd12302afca370d4f9e3d53d005fd
7655f9c32168d9e0173c425e98a25ed65198105cbb003cffdc9a8cf41d50c9e5
617dfa2021595eac153fd1ab6b0f98ac58cc319d768205d9fadc1b512bde5195
a35db11849b5fbbafd1670fc6b11cf260763a9afad95e6f762a4b9c93e76d776
dd3c3cbb29f671ef8910fe89c1140d7b52eab5cd1cce3f135de158e041768753
910ee3c94a0d21e52fa17824b8af7d5289b1c1cb46e02255ea8f93f2ef90f4db
c4351e5cc2664d169c1586d302eeea9a23bd11719d2861cc7e684c1ff442136e
603f0c558af47b01e30922ae2a3d0225f9d27be633aac8f605ee85f8b8c1e97d
a77d5ef4701bf6b337148e14c8452f91e1e4ef37e1d773095a7663abf64bbc0e
5370284c7896939fe4fccb419a9d1e35a322d608b3219383054d7a09198a67e6
ecdb6b3c19746c6d07981648bf2d9a8202437cf46383d45af74f9159198b8303
b0f302471fd7cb443f96ef97974a806bcdf98c57f23db1490cc849f167924647
c200c316787cd9de73aee3fec2aa9ea6dd77920475b34942ae5f3cdfcd3b4e1b
646f1324803055ca778a0fedf5befcb898f7b1d9d73547c3b3e41b7c34fa3c05
dc3395d2df28d50470e74da47ce0b75d6e489243f63013c48d1250604cc41f11
000bfb6da506d1e7edadb50385ccf44ed0a13e1720fa075aae3a1699f00e883a
de4cbe4003823b69c37749ddca8217377763d35657485e9d1607f81ab413d068
88bfa84b2c93a6ec8c0141a8ce112bc6cf91c41a797302f5b3cf44d92a2ed78e
68efb240a6fbc4e6c01762f44850bbfec4826467ffe22f609388a3501ad664f8
Domains
connectivity-check.ubuntu.com
google.com
cdn.fwupd.org
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
settings-win.data.microsoft.com
www.bing.com
ocsp.digicert.com
client.wns.windows.com
activation-v2.sls.microsoft.com
login.live.com
crl.microsoft.com
go.microsoft.com
www.microsoft.com
self.events.data.microsoft.com
oneocsp.microsoft.com
nexusrules.officeapps.live.com
arc.msn.com
fd.api.iris.microsoft.com
api.snapcraft.io
URLs
http://connectivity-check.ubuntu.com/
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 1292
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 1586
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 3183
comments 0

Gunra Ransomware: The New Double-Extortion Menace

Key Takeaways:

  1. Gunra ransomware uses a double-extortion model: encryption and data exfiltration/leak threats.
  2. Gunra attacks cut across sectors (manufacturing, real-estate, healthcare, pharmaceuticals) and regions (Japan, Egypt, Italy, Panama, Argentina).
  3. On endpoints Gunra executes sophisticated techniques: anti-debugging, process injection, shadow-copy deletion, file enumeration + encryption (".ENCRT") and ransom note drop.
  4. Detection must be behavior-based: look for shadow copy deletion, WMI abuse, unusual encryption patterns, Tor/.onion connections.
  5. Prevention is not one-dimensional: it requires endpoint hygiene (EDR), network segmentation, backups (offline/immutable), least privilege, phishing training.
  6. Leverage threat intelligence for rapid validation: during investigations of suspicious files, domains, or IP addresses, services like TI Lookup provide instant validation against known Gunra indicators.

You can also use TI Lookup to contextualise Gunra’s campaigns and defend proactively. Search by the threat’s name and analyze its sandbox detonations with full kill chains, IOCs, and TTPs.

threatName:"Gunra"

Gunra Sandbox analyses found via TI Lookup Gunra samples Sandbox analyses found via TI Lookup

  1. Use sandbox analysis to reveal Gunra's true behavior: static analysis alone cannot reveal the malware’s sophisticated multi-stage execution, anti-debugging tricks, and encryption techniques. ANY.RUN's Interactive Sandbox allows security teams to safely observe Gunra in action, extracting behavioral indicators, network communications, and file system modifications that inform detection rules and incident response procedures.

View Gunra sample analysis.

Gunra sample in the Sandbox Gunra sample detonated in the Sandbox

What is Gunra Malware?

Gunra is a modern ransomware strain believed to be based on the leaked Conti ransomware source code, written in C/C++, and specifically designed to target Windows and Linux operating systems. The malware employs advanced encryption methods combining ChaCha20 symmetric encryption with RSA-2048 asymmetric keys, making unauthorized decryption virtually impossible without the attackers' private key.

Upon execution it enumerates running processes and system information, detects debugging tools, injects into trusted processes, deletes Volume Shadow Copies (via Windows Management Instrumentation (WMI)), then begins encryption of files (appending a “.ENCRT” extension) and drops a ransom note “R3ADM3.txt” in every folder.

The malware not only encrypts victims' files but simultaneously exfiltrates sensitive data, threatening to publish stolen information on Tor-hosted leak sites if ransom demands are not met.

The ransomware group behind Gunra operates with clear financial motivation, utilizing professional infrastructure including negotiation portals styled after messaging applications like WhatsApp, complete with assigned roles such as "Manager" to facilitate communication with victims. This level of organization suggests a well-resourced operation capable of sustained campaigns against high-value targets.

The group's strategy emphasizes speed: victims must initiate contact within five days, or stolen data, often terabytes in volume, is published on underground forums. This urgency, combined with free decryption of sample files as proof-of-concept, has pressured organizations into rapid negotiations, with demands ranging from $7 million to $10 million, though inconsistent pricing suggests an evolving operation.

Attackers maintain an active data leak site on the dark web where they publicly shame victims who refuse to pay, a tactic designed to maximize pressure and demonstrate their willingness to follow through on threats.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Gunra Ransomware Victimology

Gunra exhibits a broad, opportunistic victimology, prioritizing industries with high-value data and operational dependencies over geographic or size-based selectivity. Primary sectors include manufacturing (six confirmed victims, the most targeted), healthcare, pharmaceuticals, real estate, electronics, beverage production, energy, and IT services.

The group avoids U.S.-based entities, focusing instead on international operations in Asia (Japan, South Korea, Taiwan), the Middle East (UAE, Egypt), Latin America (Brazil, Panama, Argentina), Europe (Italy, Turkey, Canada), and beyond.

Mid-sized to large enterprises dominate the victim pool, with examples like energy firms and hospitals facing 8-40 TB data exfiltration. This pattern aligns with double-extortion goals, exploiting sectors where downtime or data exposure incurs regulatory fines, reputational damage, or supply chain disruptions.

As of October 2025, Gunra's DLS lists 19 victims, with a surge in manufacturing and critical infrastructure attacks signaling intent to escalate against high-impact targets

How Gunra Functions

Gunra ransomware gains initial access primarily through phishing emails with malicious attachments or links, exploiting human error to deliver payloads via exploit kits. Weak Remote Desktop Protocol (RDP) configurations serve as another vector, allowing brute-force or credential-stuffing entry.

Once inside, the DONOT loader deploys the ransomware, enabling lateral movement via SMB shares, PsExec, or WMI for network propagation. It spreads by enumerating domains, injecting into remote processes, and exploiting unpatched vulnerabilities in Windows/Linux environments.

Cross-platform binaries facilitate hybrid network traversal, while obfuscation evades EDR tools during exfiltration over Tor or proxies. Post-compromise, it self-propagates to mapped drives, ensuring widespread encryption before detection

Upon initial execution, the malware creates a unique mutex to prevent multiple instances from running simultaneously, ensuring efficient resource utilization and avoiding detection anomalies that might result from duplicate processes. It immediately calls GetNativeSystemInfo to assess the host system's capabilities, sizing its thread pool based on available CPU cores to maximize encryption speed.

The reconnaissance phase involves system enumeration, with the malware cataloging running processes, installed software, network configurations, and available storage volumes. This intelligence gathering allows Gunra to identify high-value targets like database servers, file shares, and backup systems. The malware uses functions like FindNextFileExW to recursively scan directories and build a target list of files matching specific extensions.

Before encryption begins, Gunra executes its anti-recovery procedures, systematically deleting Volume Shadow Copies through WMI commands. The malware may also terminate processes associated with backup software, database management systems, and security tools that could interfere with encryption or detect the attack in progress.

For each file, Gunra generates a unique ChaCha20 key, encrypts the file content, then encrypts that ChaCha20 key with the RSA public key hardcoded in the malware. This ensures that even if victims obtain the malware sample, they cannot decrypt their files without the attackers' RSA private key. The Linux variant includes additional flexibility, supporting partial encryption modes where only portions of large files are encrypted—dramatically accelerating the attack while still rendering files unusable.

Throughout execution, Gunra maintains minimal network communication, with the RSA public key embedded in the malware itself rather than retrieved from command-and-control servers. This reduces network traffic indicators that security tools might detect. The malware also employs obfuscation techniques and anti-debugging checks to hinder analysis by security researchers. Upon completing encryption, Gunra leaves behind ransom notes containing instructions for accessing the Tor-based negotiation portal, where victims can communicate with attackers to discuss decryption payment terms.

Gunra Ransomware Real-Time Sample Analysis

ANY.RUN’s Interactive Sandbox allows to observe Gunra’s tactics in action

View analysis.

The ransomware collects general information about the runtime environment.

Gunra performs reconnaissance Gunra performs reconnaissance

If the system passes all checks, the encryption process begins. The typical extension added by Gunra is .ENCRT.

Gunra encrypting files Gunra encrypting files

A ransom note usually named R3ADM3.txt is generated and is placed in each encrypted directory. Here is a typical snippet:

Gunra’s ransome note An extract from Gunra’s ransom note

The note emphasizes urgency (5 days to make contact), offers free decryption of test files, and threatens data leakage, directing victims to a Tor site for negotiations.

Also, in many cases, Gunra deletes shadow copies via WMIC, with the command following the pattern:

cmd.exe /c C:\Windows\System32\wbem\WMIC.exe shadowcopy where "ID='{id}'" delete

The command is executed with different IDs. This prevents system recovery through VSS, enhancing the attack's impact and minimizing the chances of independent data recovery.

Gathering Threat Intelligence on Gunra Malware

Threat intelligence provides early warnings about Gunra’s campaigns, leak sites (.onion URLs), known victims, TTPs (techniques, tactics, procedures) and IOCs (hashes, IPs, domains). This intelligence enables organizations to proactively hunt for signs of compromise, block malicious infrastructure, and tailor detection/prevention controls.

Search TI Lookup with the threat name and a region ID to sort out Gunra samples analyzed by Sandbox users from your country and be aware of the trends:

threatName:"Gunra" and submissionCountry:"NG"

Gunra samples submitted from Nigeria Gunra samples submitted to the Sandbox from Nigeria

Nigeria has been one of the first targeted regions, but as we can see it’s not being under Gunra’s pressure recently.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Gunra ransomware is a potent and rapidly emerging threat: blending advanced evasion, encryption and data exfiltration in a double-extortion model. Organisations across sectors must take it seriously: not just as an endpoint or IT issue but as a business risk encompassing operations, legal/regulatory, reputational and financial exposures.

Defending effectively requires combining strong endpoint/network controls, backup and recovery strategies, detection/response capabilities, threat intelligence and sandbox-driven analytics. By anticipating threats like Gunra, organisations improve their resilience and reduce the likelihood of becoming the next victim.

Start gathering actionable threat intelligence on Gunra by signing up to ANY.RUN’s TI Lookup: protect your business with timely detection and response.

HAVE A LOOK AT

JOMANGY screenshot
JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.
Read More
OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More
Cobalt Strike screenshot
Cobalt Strike
cobaltstrike
Cobalt Strike is a legitimate penetration software toolkit developed by Forta. But its cracked versions are widely adopted by bad actors, who use it as a C2 system of choice for targeted attacks.
Read More
Neptune RAT screenshot
Neptune RAT is a Visual Basic .NET remote access trojan that gives attackers full control over infected Windows machines while stealing credentials from 270+ applications, hijacking cryptocurrency transactions, spying on victims in real time, and, in its most destructive mode, wiping the operating system entirely. Marketed openly on GitHub, Telegram, and YouTube as the "Most Advanced RAT," it is distributed under a malware-as-a-service model.
Read More
Phobos screenshot
Phobos
phobos ransomware
Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.
Read More
Godfather screenshot
Godfather
godfather
The Godfather malware is an Android banking Trojan capable of bypassing MFA that targets mobile banking and cryptocurrency applications. Known for its ability to evade detection and mimic legitimate software, it poses a significant threat to individuals and organizations by stealing sensitive data and enabling financial fraud.
Read More