Attribution
Financially motivated ransomware-as-a-service (RaaS) operation. No confirmed nation-state attribution. Reporting links Gunra's Windows encryptor to the leaked Conti ransomware source code, placing it in the post-Conti lineage alongside families such as Black Basta and Rhysida. The FBI-led joint advisory notes the operators rebranded under the alias 'Golden Community' while building out an affiliate program.
Motivation
Financial (double-extortion ransomware; data theft plus encryption for extortion)
Attribution confidence
medium
Sectors
Healthcare, manufacturing, professional services
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting UAE, Egypt (Healthcare, manufacturing, professional services sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.