Gunra 랜섬웨어 분석 보고서

2025-07-25 Genians Gunra Ransomware Analysis Report

https://www.genians.co.kr/blog/gunra

Thumbnail for Gunra 랜섬웨어 분석 보고서

Genians analyzed Windows and Linux variants of Gunra ransomware, a family first observed in April 2025 with code-structure similarities to leaked Conti source code. The Windows build enumerates drives and user directories, excludes selected system and security-related paths, encrypts files with ChaCha20, protects keys with RSA-2048, appends the CRYPT extension, and creates R3adm3.txt ransom notes. It also queries and deletes Volume Shadow Copies through WMI and WMIC to inhibit recovery. The Linux build supports command-line options for target paths, extensions, thread counts, encryption ratio, key files, storage paths, and size limits, then uses threaded ChaCha20 encryption and renames files with the .ENCRT extension. The report maps these behaviors to Genian EDR detections for IoC-based execution, mass document renaming, shadow copy deletion, and repeated ransom-note creation.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 22c47ec98718ab243f2f474170366a1… 2025-07-25 2025-10-22
HASH 91f8fc7a3290611e28a35a403fd8155… 2025-07-25 2025-08-27

Related Reports

« Back