Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Gunra is a double-extortion ransomware operation first observed in April 2025. Its Windows encryptor reuses techniques and code derived from the leaked Conti source, and the group runs a Tor-based data-leak/negotiation site. Victims find a ransom note in each affected directory directing them to a Tor negotiation portal (Client ID + initial password), then to negotiate via qTox within roughly 5-7 days under threat of publication. In mid-2025 the operators added a configurable Linux/ESXi-oriented variant, and by early 2026 they had expanded into a structured RaaS affiliate program advertised on dark-web forums (management panel, configurable builder, cross-platform lockers). A multi-agency #StopRansomware advisory (AA26-222A) was published in August 2026.
Gunra surfaced in April 2025 with a Windows locker built on leaked Conti code, immediately operating a double-extortion model: exfiltrate data, encrypt, and threaten publication on a Tor data-leak site. Trend Micro documented a Linux variant on 29 July 2025 that is notably configurable - up to 100 parallel encryption threads, partial/selective encryption via ratio and limit parameters, and optional storage of RSA-encrypted keys in separate keystore files; unlike the Windows build, the Linux variant drops no ransom note and focuses purely on fast encryption. Researchers also flagged a weak, time-seeded RNG in the Linux variant that may permit key reconstruction and recovery. Through 2025-2026 Gunra scaled from a single crew into a RaaS operation, rebranding under the alias 'Golden Community' and recruiting penetration testers / initial-access brokers. The August 2026 joint advisory (FBI, CISA, DC3, NSA, USSS, and South Korea's National Police Agency; AA26-222A) reported initial access via internet-facing firewall/VPN appliances including Fortinet FortiOS/FortiProxy flaws (CVE-2024-55591, CVE-2025-24472) and SSH/credential-exposure weaknesses. Victimology skews toward manufacturing, healthcare, and professional services, with the heaviest concentrations in the Republic of Korea, Brazil, Spain, and other Asia-Pacific, Latin American, and European targets; leak-site tracking (ransomware.live) recorded on the order of ~50+ claimed victims across ~28 countries, with listings continuing into September 2026. Reporting is recent and still consolidating, so some campaign-level detail remains thin. MENA relevance: Real but small. Gunra's leak site does carry MENA victims that back RaqibCTI's UAE and Egypt tags - UAE listings include American Hospital Dubai (healthcare) and a Dubai building-contracting firm, and Egypt includes a hospital/healthcare entity (Dar Al Teb) dated to the group's April 2025 emergence. These are genuine leak-site claims (unpaid extortion listings, not independently confirmed breaches), and MENA is a minor slice of overall victimology dominated by APAC/LATAM/Europe. Verdict: UAE and Egypt tags = REAL leak-site victims, low volume; MENA is opportunistic, not a deliberate regional focus.
+13 more relationships — see the relationships browser.