Gunra 랜섬웨어

2025-10-29 Ahnlab Gunra Ransomware

https://cloudimg.ccs.ahnlab.com/img_upload/product/2510307892075260.pdf

Attachments

2510307892075260.pdf (5 MB)

AhnLab ASEC analyzes Gunra ransomware, a double-extortion group active since April 2025 that targets Windows and Linux systems and has affected organizations in South Korea, Japan, Egypt, Panama, Italy, Argentina, and other countries. The Linux ELF variant supports file and disk encryption, takes command-line options for thread count, target paths, extensions, RSA key path, and encryption limits, and uses ChaCha20 with RSA-protected keys. Its Linux key and nonce generation relies on time-seeded rand(), which may make recovery feasible by reconstructing likely key material. The Windows EXE variant uses MurmurHash2-based API resolution, creates the mutex kjsidugiaadf99439, deletes Volume Shadow Copies through WMI, drops R3ADM3.txt, and uses CryptGenRandom() with ChaCha8, making the weak-PRNG recovery path impractical. Public IoCs are not listed in the PDF, with detailed indicators and AhnLab detections reserved for AhnLab TIP.

Related Reports

« Back