Gunra Ransomware 분석

2025-08-25 Piolink Gunra Ransomware Analysis

https://www.piolink.com/kr/service/Security-Analysis.php?bbsCode=security&vType=view&idx=152&page=2

Thumbnail for Gunra Ransomware 분석

PIOLINK describes Gunra ransomware expanding from Windows systems to Linux variants after activity first appeared in April 2025, suggesting the operators are broadening their target platforms. Reported activity has affected organizations in Taiwan, the United States, and South Korea across government, healthcare, manufacturing, and energy sectors. The Linux variant requires parameters for thread count, target path, extensions, encryption ratio, and RSA public key file, then encrypts files with ChaCha20, protects generated keys with RSA, and renames encrypted files with the .ENCRT extension without creating a ransom note. The Windows variant does not require command-line parameters, creates a mutex to prevent duplicate execution, checks for Explorer.exe, uses ChaCha/RSA encryption, renames files with the same extension, and drops R3ADM3.txt ransom notes in each folder.

Related Reports

« Back