Inside Gunra RaaS: From Affiliate Recruitment on the Dark Web to Full Technical Dissection of their Locker

2026-02-11 Cloud SEK

https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker

Thumbnail for Inside Gunra RaaS: From Affiliate Recruitment on the Dark Web to Full Technical Dissection of their Locker

CloudSEK infiltrated Gunra's newly launched ransomware affiliate program and obtained panel access, operator documentation, and a working locker sample. The analyzed Windows payload encrypts files with per-file ChaCha20 keys protected by RSA-4096, processes files in parallel, excludes system-critical paths and extensions, and operates without network connectivity. It renames encrypted files with `.ENCRT`, creates `R3ADM3.txt` ransom notes, and can store protected key material in SHA-256-named keystore files.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 75e5621756e9d19efeac2bcbb2ac471… 2026-02-11 2026-02-11
HASH 25c8cb27947042de89d634b3e260e61… 2026-02-11 2026-02-11
HASH e57b130718373f6ba9b37f39ca1d7e3d 2026-02-11 2026-02-11

Related Reports

« Back