Financially motivated ransomware-as-a-service (RaaS) operation. No confirmed nation-state attribution. Reporting links Gunra's Windows encryptor to the leaked Conti ransomware source code, placing it in the post-Conti lineage alongside families such as Black Basta and Rhysida. The FBI-led joint advisory notes the operators rebranded under the alias 'Golden Community' while building out an affiliate program.
First seen
2025-04
Last active
2026-09
Motivation
Financial (double-extortion ransomware; data theft plus encryption for extortion)
Attribution confidence
medium
MENA targeting
UAE, Egypt
Sectors
Healthcare, manufacturing, professional services
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting UAE, Egypt (Healthcare, manufacturing, professional services sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
CISA AA26-222A: OpenSSH downloaded from external servers (T1105) and used for SSH tunneling to maintain persistent connections between compromised hosts.
CISA AA26-222A / CYFIRMA: encryptor enumerates drives A-Z via FindFirstFileW/FindNextFileW(ExW) to select target files by extension; operators traversed directory structures for user data.
CISA AA26-222A: RDP used to reach internal VDI, authentication servers, Active Directory and IT staff desktops.
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Gunra's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 7 techniques
Defender for Cloud AppsT1133partialDefender for Cloud AppsT1567partialID ProtectionT1556minimalID ProtectionT1556.006significantIdentity Secure ScoreT1550partialIdentity Secure ScoreT1550.002partialPrivileged Identity ManagementT1556minimalPrivileged Identity ManagementT1556.006significantRole Based Access ControlT1556minimalRole Based Access ControlT1556.006partialAudit SolutionsT1556partialAudit SolutionsT1556.006partialInformation ProtectionT1070significantInformation ProtectionT1567significant
detect · 13 techniques
App GovernanceT1556significantApp GovernanceT1556.006significantAdvanced Threat HuntingT1556significantAdvanced Threat HuntingT1556.006significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1133partialDefender for Cloud AppsT1486partialDefender for Cloud AppsT1567partialMicrosoft Defender for IdentityT1003minimalMicrosoft Defender for IdentityT1003.003minimalMicrosoft Defender for IdentityT1021minimalMicrosoft Defender for IdentityT1021.002minimalMicrosoft Defender for IdentityT1133minimal
respond · 4 techniques
Automated Investigation and ResponseT1550significantAutomated Investigation and ResponseT1567significantIncident ResponseT1550minimalIncident ResponseT1556minimalIncident ResponseT1556.006minimalATT&CK Simulation TrainingT1550partial
Countermeasures · D3FEND
Defensive techniques that counter Gunra's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.