Inside Gunra RaaS: From Affiliate Recruitment on the Dark Web to Full Technical Dissection of their Locker
2026-02-11 • Cloud SEK •
CloudSEK infiltrated Gunra's newly launched ransomware affiliate program and obtained panel access, operator documentation, and a working locker sample. The analyzed Windows payload encrypts files with per-file ChaCha20 keys protected by RSA-4096, processes files in parallel, excludes system-critical paths and extensions, and operates without network connectivity. It renames encrypted files with `.ENCRT`, creates `R3ADM3.txt` ransom notes, and can store protected key material in SHA-256-named keystore files.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 75e5621756e9d19efeac2bcbb2ac471… | 2026-02-11 | 2026-02-11 |
| HASH | 25c8cb27947042de89d634b3e260e61… | 2026-02-11 | 2026-02-11 |
| HASH | e57b130718373f6ba9b37f39ca1d7e3d | 2026-02-11 | 2026-02-11 |
Related Reports
2026-03-12 •
60% Match
Shares tags: Ransomware, Gunra • Published within a month
2026-07-30 •
45% Match
#Phishing
#Ransomware
#Wateringhole
#SIGNBT
#Gunra
#Copperhedge
#DoubleBarrel
Shares tags: Ransomware, Gunra
2026-07-30 •
45% Match
Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)
Ahnlab
Shares tags: Ransomware, Gunra
Shares tags: Ransomware, Gunra
Shares tags: Ransomware, Gunra
Shares tags: Ransomware, Gunra