Gunra is a Conti-derived ransomware family and ransomware-as-a-service operation first observed in 2025. It initially appeared in attacks against South Korean organizations and later expanded into a broader global extortion operation affecting sectors including healthcare, manufacturing, IT, pharmaceuticals, real estate, and other enterprise environments. Gunra has been associated with double-extortion activity in which operators steal data before encrypting systems and threaten publication through Tor-based leak infrastructure if victims do not pay.
Gunra supports both Windows and Linux environments, and reporting also indicates affiliate marketing that advertised broader cross-platform support. On Windows, Gunra encrypts files, appends a characteristic encrypted-file extension, and drops ransom notes in affected directories. It has been observed enumerating files and processes, collecting system information, deleting shadow copies, and using anti-analysis checks such as debugger detection. It also disables or interferes with backup and security controls to hinder recovery. On Linux, Gunra was developed into a compact ELF locker targeting enterprise servers and avoiding certain critical system directories to preserve system operability during extortion. Linux variants have also been reported modifying authentication, privilege, scheduled-task, and startup-related configurations to maintain access or facilitate post-compromise operations.
Gunra evolved from early Conti-based code into a more mature affiliate-driven platform with centralized management features for payload generation, negotiation, and branding. By early 2026 it had transitioned into a formal RaaS model, recruiting affiliates on criminal forums and enabling white-label use that could cause technically related attacks to appear under different names. Operators have been reported to participate directly in negotiations, indicating centralized oversight beyond simple payload leasing.
Gunra intrusions have been linked to multiple initial-access patterns. High-confidence reporting ties some South Korean incidents to exploitation of vulnerabilities in locally deployed financial security software through watering-hole attacks on compromised legitimate websites, as well as spearphishing. In those cases, Gunra activity overlapped technically with a separate espionage-focused intrusion cluster dubbed Operation Double Barrel, including shared exploit paths, tooling characteristics, infrastructure elements, and anti-forensic behavior. Assessments indicate Gunra and the espionage actor were likely distinct operators with different end goals, but may have shared tools, infrastructure, access, or collaborated in a limited manner. Some reporting specifically notes overlap with activity attributed to Lazarus, though definitive attribution of Gunra itself to a state actor is not established.
Gunra is primarily used for financially motivated extortion. Its operational model combines encryption, data theft, anti-forensic measures, and affiliate enablement, making it a notable emerging ransomware threat across both workstation and server environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The technical report from cybersecurity firm AhnLab details how the state-sponsored North Korean group, widely tracked as Lazarus, and the Gunra ransomware scheme ran parallel campaigns against South Korean targets from 2025 through the first half of this year, differing only in their final objective.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
In the RaaS model described by S2W, Gunra provides a web-based panel that affiliates use to manage attacks, track victims, and handle payments.
Behavioral Profile: What It Does on a Live System ... Modifies init.d / rc scripts ... Modifies Bash startup scripts ... MITRE ATT&CK Mapping ... Persistence Boot or Logon Initialization Scripts T1037
Behavioral Profile: What It Does on a Live System ... Creates/modifies cron jobs ... MITRE ATT&CK Mapping ... Persistence Scheduled Task/Job: Cron T1053.003
Behavioral Profile: What It Does on a Live System ... Modifies init.d / rc scripts ... Modifies Bash startup scripts ... MITRE ATT&CK Mapping ... Persistence Boot or Logon Initialization Scripts T1037
This includes “obfuscation of malicious activity, avoidance of rule-based detection systems, strong encryption methods, ransom demands, and warnings to publish data on underground forums.”
"final cleanup: shutting down the thread pool, zeroing out sensitive memory (including encryption keys), and exiting cleanly"
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Gunra is a ransomware operation that used access obtained through exploitation of Korean financial security software vulnerabilities to encrypt files, steal data, and demand extortion payments. The group later transitioned to a ransomware-as-a-service model and operates a double-extortion scheme with a Tor-based leak site.
Ransomware-as-a-service operation mentioned because a separate intrusion shared initial-access vulnerability, filenames, execution patterns, SSH key fingerprint, and infrastructure with the state-sponsored campaign. S2W said it moved from Conti-derived ransomware to its own Windows and Linux builds.
Ransomware used in related attacks that exploited the same financial security software vulnerabilities to encrypt files and exfiltrate sensitive organizational information.
Ransomware used in a related attack case that exploited the same financial security software vulnerabilities, encrypted files, and exfiltrated sensitive organizational data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.