#Gunra

Incident/Operation

2025-07-25 • Gunra 랜섬웨어 분석 보고서

Gunra is a Conti-influenced ransomware-as-a-service operation first observed in April 2025 and organized as an affiliate program in early 2026. Affiliates target governments, critical infrastructure, and commercial organizations, commonly exploiting internet-facing firewalls or VPN appliances and weak or stolen credentials. Gunra uses double extortion by exfiltrating sensitive data before encrypting Windows or Linux systems and threatening publication or sale; reporting also notes cross-platform expansion and possible, but unconfirmed, limited sharing of access methods, tools, or infrastructure with a separate state-sponsored actor.

Tagged Reports

« Back