#Gunra
Incident/Operation
2025-07-25 • Gunra 랜섬웨어 분석 보고서
Gunra is a Conti-influenced ransomware-as-a-service operation first observed in April 2025 and organized as an affiliate program in early 2026. Affiliates target governments, critical infrastructure, and commercial organizations, commonly exploiting internet-facing firewalls or VPN appliances and weak or stolen credentials. Gunra uses double extortion by exfiltrating sensitive data before encrypting Windows or Linux systems and threatening publication or sale; reporting also notes cross-platform expansion and possible, but unconfirmed, limited sharing of access methods, tools, or infrastructure with a separate state-sponsored actor.
-
15
Tagged Reports
-
11
Unique Authors
-
382
Active Days