Gunra is a ransomware group first observed in April 2025. It is also referred to as Data Publish, a name derived from its leak site, and has been tracked under aliases including gunra_ransomware. The operation was built from leaked Conti v2 source code and by January 2026 had transitioned to a ransomware-as-a-service model. Gunra conducts double-extortion intrusions, stealing data before encrypting systems and threatening publication on its leak site to pressure victims. Gunra initially targeted South Korean organizations and later expanded globally. Confirmed victimology includes organizations in South Korea, Thailand, Malaysia, the United States, France, Spain, Uruguay, Hong Kong, Venezuela, Brazil, the Bahamas, and Vietnam. Reported targets span government and public-sector entities, cryptocurrency exchanges, IT service providers, healthcare, manufacturing, financial services, business services, hospitality, transportation and logistics, and broader healthcare-related organizations in EMEA. The group has been linked to campaigns exploiting vulnerabilities in Korean financial security software through watering-hole and spear-phishing operations. In these cases, attackers compromised legitimate Korean websites across sectors including media, education, healthcare, and manufacturing, then redirected selected visitors to exploit infrastructure that triggered software flaws and delivered malware. Gunra intrusions associated with this activity culminated in file encryption, data theft, and extortion. Researchers also documented overlap between Gunra ransomware incidents and a parallel espionage-focused campaign associated with North Korean Lazarus activity, including shared initial-access vulnerabilities, malware naming and execution patterns, privilege-escalation tooling, command-and-control infrastructure, and similar anti-forensic deletion behavior. The available evidence supports a high-likelihood technical linkage or limited collaboration, shared tooling, or shared access, but does not conclusively establish that Gunra and Lazarus are the same actor. Gunra’s observed capabilities include initial access via exploitation of vulnerable internet-facing or client-side security software, watering-hole delivery, spear-phishing, privilege escalation, data exfiltration, ransomware deployment, and anti-forensic cleanup. The group has also been associated with post-compromise behaviors consistent with broader human-operated ransomware activity, including use of shared tooling and infrastructure and extortion based on stolen organizational data. Its dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group targeting South Korean organizations and other global victims, exploiting the same Korean financial security software vulnerabilities as Lazarus. It used access for file encryption, data theft, and extortion, and appears technically linked to Lazarus through shared infrastructure, tooling, and tradecraft.
Ransomware-as-a-service operation whose intrusions overlapped technically with the state-sponsored campaign, including shared initial access path, filenames, SSH fingerprint, infrastructure, and anti-forensic behavior; the report stops short of saying the same operator was responsible.
Conducting a ransomware attack against Siam Stabilizers and Chemicals Co., Ltd. / SSC.
Referenced as a ransomware group discussed in relation to a state-sponsored threat actor in Operation Double Barrel.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.