Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Gunra

158
Global rank
132 infographic chevron month
Month rank
114 infographic chevron week
Week rank
0
IOCs

Gunra ransomware, a financially motivated threat actor that emerged in April 2025, deploys double-extortion tactics to encrypt victims' data and threaten leaks of exfiltrated information, primarily targeting Windows and Linux systems across healthcare, manufacturing, and other sectors worldwide.

Ransomware
Type
Unknown
Origin
1 April, 2025
First seen
26 August, 2026
Last seen
Also known as
Conti

How to analyze Gunra with ANY.RUN

Type
Unknown
Origin
1 April, 2025
First seen
26 August, 2026
Last seen

IOCs

IP addresses
151.101.130.49
185.125.190.56
185.125.190.101
185.125.190.57
91.189.91.98
185.125.190.99
23.52.181.141
48.192.1.64
48.209.133.15
57.153.246.3
74.178.76.128
23.216.77.36
135.233.95.135
92.123.104.52
48.209.138.168
23.52.181.212
172.211.123.250
2.23.246.101
23.11.41.157
20.190.160.22
Hashes
5677dfad26045e271272bc98be2fd24e2f6d13737850ab1d9857fd58de05e9f9
854e5f77f788bbbe6e224195e115c749172cd12302afca370d4f9e3d53d005fd
7655f9c32168d9e0173c425e98a25ed65198105cbb003cffdc9a8cf41d50c9e5
617dfa2021595eac153fd1ab6b0f98ac58cc319d768205d9fadc1b512bde5195
a35db11849b5fbbafd1670fc6b11cf260763a9afad95e6f762a4b9c93e76d776
dd3c3cbb29f671ef8910fe89c1140d7b52eab5cd1cce3f135de158e041768753
910ee3c94a0d21e52fa17824b8af7d5289b1c1cb46e02255ea8f93f2ef90f4db
c4351e5cc2664d169c1586d302eeea9a23bd11719d2861cc7e684c1ff442136e
603f0c558af47b01e30922ae2a3d0225f9d27be633aac8f605ee85f8b8c1e97d
a77d5ef4701bf6b337148e14c8452f91e1e4ef37e1d773095a7663abf64bbc0e
5370284c7896939fe4fccb419a9d1e35a322d608b3219383054d7a09198a67e6
ecdb6b3c19746c6d07981648bf2d9a8202437cf46383d45af74f9159198b8303
b0f302471fd7cb443f96ef97974a806bcdf98c57f23db1490cc849f167924647
c200c316787cd9de73aee3fec2aa9ea6dd77920475b34942ae5f3cdfcd3b4e1b
646f1324803055ca778a0fedf5befcb898f7b1d9d73547c3b3e41b7c34fa3c05
dc3395d2df28d50470e74da47ce0b75d6e489243f63013c48d1250604cc41f11
000bfb6da506d1e7edadb50385ccf44ed0a13e1720fa075aae3a1699f00e883a
de4cbe4003823b69c37749ddca8217377763d35657485e9d1607f81ab413d068
88bfa84b2c93a6ec8c0141a8ce112bc6cf91c41a797302f5b3cf44d92a2ed78e
68efb240a6fbc4e6c01762f44850bbfec4826467ffe22f609388a3501ad664f8
Domains
connectivity-check.ubuntu.com
google.com
cdn.fwupd.org
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
settings-win.data.microsoft.com
www.bing.com
ocsp.digicert.com
client.wns.windows.com
activation-v2.sls.microsoft.com
login.live.com
crl.microsoft.com
go.microsoft.com
www.microsoft.com
self.events.data.microsoft.com
oneocsp.microsoft.com
nexusrules.officeapps.live.com
arc.msn.com
fd.api.iris.microsoft.com
api.snapcraft.io
URLs
http://connectivity-check.ubuntu.com/
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2536
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7351
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10494
comments 0

Gunra Ransomware: The New Double-Extortion Menace

Key Takeaways:

  1. Gunra ransomware uses a double-extortion model: encryption and data exfiltration/leak threats.
  2. Gunra attacks cut across sectors (manufacturing, real-estate, healthcare, pharmaceuticals) and regions (Japan, Egypt, Italy, Panama, Argentina).
  3. On endpoints Gunra executes sophisticated techniques: anti-debugging, process injection, shadow-copy deletion, file enumeration + encryption (".ENCRT") and ransom note drop.
  4. Detection must be behavior-based: look for shadow copy deletion, WMI abuse, unusual encryption patterns, Tor/.onion connections.
  5. Prevention is not one-dimensional: it requires endpoint hygiene (EDR), network segmentation, backups (offline/immutable), least privilege, phishing training.
  6. Leverage threat intelligence for rapid validation: during investigations of suspicious files, domains, or IP addresses, services like TI Lookup provide instant validation against known Gunra indicators.

You can also use TI Lookup to contextualise Gunra’s campaigns and defend proactively. Search by the threat’s name and analyze its sandbox detonations with full kill chains, IOCs, and TTPs.

threatName:"Gunra"

Gunra Sandbox analyses found via TI Lookup Gunra samples Sandbox analyses found via TI Lookup

  1. Use sandbox analysis to reveal Gunra's true behavior: static analysis alone cannot reveal the malware’s sophisticated multi-stage execution, anti-debugging tricks, and encryption techniques. ANY.RUN's Interactive Sandbox allows security teams to safely observe Gunra in action, extracting behavioral indicators, network communications, and file system modifications that inform detection rules and incident response procedures.

View Gunra sample analysis.

Gunra sample in the Sandbox Gunra sample detonated in the Sandbox

What is Gunra Malware?

Gunra is a modern ransomware strain believed to be based on the leaked Conti ransomware source code, written in C/C++, and specifically designed to target Windows and Linux operating systems. The malware employs advanced encryption methods combining ChaCha20 symmetric encryption with RSA-2048 asymmetric keys, making unauthorized decryption virtually impossible without the attackers' private key.

Upon execution it enumerates running processes and system information, detects debugging tools, injects into trusted processes, deletes Volume Shadow Copies (via Windows Management Instrumentation (WMI)), then begins encryption of files (appending a “.ENCRT” extension) and drops a ransom note “R3ADM3.txt” in every folder.

The malware not only encrypts victims' files but simultaneously exfiltrates sensitive data, threatening to publish stolen information on Tor-hosted leak sites if ransom demands are not met.

The ransomware group behind Gunra operates with clear financial motivation, utilizing professional infrastructure including negotiation portals styled after messaging applications like WhatsApp, complete with assigned roles such as "Manager" to facilitate communication with victims. This level of organization suggests a well-resourced operation capable of sustained campaigns against high-value targets.

The group's strategy emphasizes speed: victims must initiate contact within five days, or stolen data, often terabytes in volume, is published on underground forums. This urgency, combined with free decryption of sample files as proof-of-concept, has pressured organizations into rapid negotiations, with demands ranging from $7 million to $10 million, though inconsistent pricing suggests an evolving operation.

Attackers maintain an active data leak site on the dark web where they publicly shame victims who refuse to pay, a tactic designed to maximize pressure and demonstrate their willingness to follow through on threats.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Gunra Ransomware Victimology

Gunra exhibits a broad, opportunistic victimology, prioritizing industries with high-value data and operational dependencies over geographic or size-based selectivity. Primary sectors include manufacturing (six confirmed victims, the most targeted), healthcare, pharmaceuticals, real estate, electronics, beverage production, energy, and IT services.

The group avoids U.S.-based entities, focusing instead on international operations in Asia (Japan, South Korea, Taiwan), the Middle East (UAE, Egypt), Latin America (Brazil, Panama, Argentina), Europe (Italy, Turkey, Canada), and beyond.

Mid-sized to large enterprises dominate the victim pool, with examples like energy firms and hospitals facing 8-40 TB data exfiltration. This pattern aligns with double-extortion goals, exploiting sectors where downtime or data exposure incurs regulatory fines, reputational damage, or supply chain disruptions.

As of October 2025, Gunra's DLS lists 19 victims, with a surge in manufacturing and critical infrastructure attacks signaling intent to escalate against high-impact targets

How Gunra Functions

Gunra ransomware gains initial access primarily through phishing emails with malicious attachments or links, exploiting human error to deliver payloads via exploit kits. Weak Remote Desktop Protocol (RDP) configurations serve as another vector, allowing brute-force or credential-stuffing entry.

Once inside, the DONOT loader deploys the ransomware, enabling lateral movement via SMB shares, PsExec, or WMI for network propagation. It spreads by enumerating domains, injecting into remote processes, and exploiting unpatched vulnerabilities in Windows/Linux environments.

Cross-platform binaries facilitate hybrid network traversal, while obfuscation evades EDR tools during exfiltration over Tor or proxies. Post-compromise, it self-propagates to mapped drives, ensuring widespread encryption before detection

Upon initial execution, the malware creates a unique mutex to prevent multiple instances from running simultaneously, ensuring efficient resource utilization and avoiding detection anomalies that might result from duplicate processes. It immediately calls GetNativeSystemInfo to assess the host system's capabilities, sizing its thread pool based on available CPU cores to maximize encryption speed.

The reconnaissance phase involves system enumeration, with the malware cataloging running processes, installed software, network configurations, and available storage volumes. This intelligence gathering allows Gunra to identify high-value targets like database servers, file shares, and backup systems. The malware uses functions like FindNextFileExW to recursively scan directories and build a target list of files matching specific extensions.

Before encryption begins, Gunra executes its anti-recovery procedures, systematically deleting Volume Shadow Copies through WMI commands. The malware may also terminate processes associated with backup software, database management systems, and security tools that could interfere with encryption or detect the attack in progress.

For each file, Gunra generates a unique ChaCha20 key, encrypts the file content, then encrypts that ChaCha20 key with the RSA public key hardcoded in the malware. This ensures that even if victims obtain the malware sample, they cannot decrypt their files without the attackers' RSA private key. The Linux variant includes additional flexibility, supporting partial encryption modes where only portions of large files are encrypted—dramatically accelerating the attack while still rendering files unusable.

Throughout execution, Gunra maintains minimal network communication, with the RSA public key embedded in the malware itself rather than retrieved from command-and-control servers. This reduces network traffic indicators that security tools might detect. The malware also employs obfuscation techniques and anti-debugging checks to hinder analysis by security researchers. Upon completing encryption, Gunra leaves behind ransom notes containing instructions for accessing the Tor-based negotiation portal, where victims can communicate with attackers to discuss decryption payment terms.

Gunra Ransomware Real-Time Sample Analysis

ANY.RUN’s Interactive Sandbox allows to observe Gunra’s tactics in action

View analysis.

The ransomware collects general information about the runtime environment.

Gunra performs reconnaissance Gunra performs reconnaissance

If the system passes all checks, the encryption process begins. The typical extension added by Gunra is .ENCRT.

Gunra encrypting files Gunra encrypting files

A ransom note usually named R3ADM3.txt is generated and is placed in each encrypted directory. Here is a typical snippet:

Gunra’s ransome note An extract from Gunra’s ransom note

The note emphasizes urgency (5 days to make contact), offers free decryption of test files, and threatens data leakage, directing victims to a Tor site for negotiations.

Also, in many cases, Gunra deletes shadow copies via WMIC, with the command following the pattern:

cmd.exe /c C:\Windows\System32\wbem\WMIC.exe shadowcopy where "ID='{id}'" delete

The command is executed with different IDs. This prevents system recovery through VSS, enhancing the attack's impact and minimizing the chances of independent data recovery.

Gathering Threat Intelligence on Gunra Malware

Threat intelligence provides early warnings about Gunra’s campaigns, leak sites (.onion URLs), known victims, TTPs (techniques, tactics, procedures) and IOCs (hashes, IPs, domains). This intelligence enables organizations to proactively hunt for signs of compromise, block malicious infrastructure, and tailor detection/prevention controls.

Search TI Lookup with the threat name and a region ID to sort out Gunra samples analyzed by Sandbox users from your country and be aware of the trends:

threatName:"Gunra" and submissionCountry:"NG"

Gunra samples submitted from Nigeria Gunra samples submitted to the Sandbox from Nigeria

Nigeria has been one of the first targeted regions, but as we can see it’s not being under Gunra’s pressure recently.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Gunra ransomware is a potent and rapidly emerging threat: blending advanced evasion, encryption and data exfiltration in a double-extortion model. Organisations across sectors must take it seriously: not just as an endpoint or IT issue but as a business risk encompassing operations, legal/regulatory, reputational and financial exposures.

Defending effectively requires combining strong endpoint/network controls, backup and recovery strategies, detection/response capabilities, threat intelligence and sandbox-driven analytics. By anticipating threats like Gunra, organisations improve their resilience and reduce the likelihood of becoming the next victim.

Start gathering actionable threat intelligence on Gunra by signing up to ANY.RUN’s TI Lookup: protect your business with timely detection and response.

HAVE A LOOK AT

DEVMAN screenshot
DEVMAN
devman
DEVMAN is a fast-evolving malware family targeting Windows environments with a mix of credential theft, remote control capabilities, and persistence techniques typical of modern crimeware. Initially observed in early 2025, DEVMAN quickly became a favorite tool among cybercriminal groups thanks to its stealth, modular structure, and ability to bypass traditional AV solutions.
Read More
Play Ransomware screenshot
Play aka PlayCrypt ransomware group has been successfully targeting corporations, municipal entities, and infrastruction all over the world for about three years. It infiltrates networks via software vulnerabilities, phishing links and compromised websites. The ransomware abuses Windows system services to evade detection and maintain persistence. Play encrypts user files and steals sensitive data while demanding a ransom.
Read More
Kamasers screenshot
Kamasers
kamasers
Kamasers is a multi-functional DDoS botnet malware that transforms infected machines into remotely controlled attack nodes. It combines network-layer flooding capabilities, resilient command-and-control (C2), and payload delivery, making it not just a disruption tool but a gateway to broader compromise.
Read More
VanHelsing Ransomware screenshot
VanHelsing is a sophisticated ransomware strain that appeared in early 2025, operating via the Ransomware-as-a-Service (RaaS) model and targeting primarily USA and France. It threatens mostly Windows systems but has variants for Linux, BSD, ARM, and ESXi, making it a multi-platform malware. It is also notable for its advanced evasion techniques, double extortion tactics, and rapid evolution.
Read More
Akira Ransomware screenshot
Akira Ransomware emerged in March 2023 and compromised over 250 organizations by January 2024 with approximately $42 million in ransom payments. It employs double extortion tactics exfiltrating data before encryption and threatening to publish it on a dedicated website.
Read More
PXA Stealer screenshot
PXA Stealer
pxastealer
PXA Stealer is an information-stealing malware that targets individuals and organizations in 60+ countries. It spreads via phishing, archives, and fake software updates. DLL sideloading, decoy documents, and obfuscation help it evade security tools. Exfiltrated data is exfiltrated and monetized through underground marketplaces.
Read More