SYMBOLCOMMON_NAMEaka. SYNONYMS
win.gunra (Back to overview)

Gunra


Gunra is a highly aggressive ransomware family that first emerged in April 2025, operating as a Ransomware-as-a-Service (RaaS). It is built upon the leaked source code of the notorious Conti ransomware. As a double-extortion threat, Gunra not only encrypts the victim's data but also exfiltrates sensitive business information. The threat actors then threaten to publish this stolen data on their Tor-hosted leak sites if the ransom is not paid within a strict 5-day deadline. Gunra has a global footprint, heavily targeting critical infrastructure, healthcare, pharmaceuticals, manufacturing and real estate across both Windows and Linux environments.

The name of the ransomware is derived from the malicious executable process it spawns upon infection, typically named gunraransome.exe. It systematically deletes all Volume Shadow Copies via Windows Management Instrumentation (WMI) to prevent victims from easily restoring their files. Once Gunra has secured its foothold and terminated interfering processes, it encrypts the victim's files using a combination of ChaCha20 and RSA-4096 encryption, notably featuring "step-skip" partial encryption to maximize speed. The encrypted files are easily identifiable because the malware appends the .ENCRT extension to their original filenames. In every directory where files have been encrypted, the malware drops a ransom note named R3ADM3.txt. This note informs the victim of the double extortion and provides instructions on how to contact the attackers. Victims are directed to a negotiation portal hosted on the Tor network to initiate communication, utilizing .onion addresses such as [http://gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad.onion/]

References
2026-07-30AhnLabAhnLab
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)
Gunra
2025-04-21BroadcomBroadcom
Gunra Ransomware
Gunra

There is no Yara-Signature yet.