국내 금융권을 공격한 Gunra 랜섬웨어

2025-08-27 SKShildus Gunra Ransomware Targeting the South Korean Financial Sector

https://www.skshieldus.com/report/eqstInsight/ransomware2508.html?from=content

Thumbnail for 국내 금융권을 공격한 Gunra 랜섬웨어

SK Shieldus reports that Gunra ransomware, first seen in April 2025, attacked a South Korean financial institution in July 2025, causing roughly four days of service disruption and alleged theft of 13.2 TB of database material. The group operates a Tor leak site that lists victims, stolen-data types, posting dates, and negotiation deadlines, then escalates pressure by publishing previews or threatening full disclosure when negotiations fail. Gunra’s Linux variant accepts parameters for threads, target path, extensions, encryption ratio, RSA public key file, key storage, and encryption limits, using ChaCha20 with partial 1 MB encryption intervals and separate or appended key storage. The Windows variant runs without command-line parameters, creates a mutex, drops R3ADM3.txt ransom notes, excludes selected system paths and file types, and applies different encryption strategies to database and virtual-machine files.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 22c47ec98718ab243f2f474170366a1… 2025-07-25 2025-10-22
HASH 91f8fc7a3290611e28a35a403fd8155… 2025-07-25 2025-08-27

Related Reports

« Back