Netskope Threat Labs

Gunra

ATP Sandbox Adv. HeuristicsAV

Gunra is a ransomware as a service operation that emerged in April 2025 and builds on the leaked source code of the Conti ransomware. It exfiltrates business data before encrypting files with ChaCha20 and RSA-4096 cryptography, appends the .ENCRT extension, and drops ransom notes that direct victims to a Tor based negotiation portal under a five day deadline. Campaigns have targeted critical infrastructure, healthcare, pharmaceuticals, manufacturing, and real estate across Windows and Linux environments.

First seen
June 2025
Last seen
October 2026
Alert Name
Gen:Variant.Linux.Ransom.Gunra.1
Gen:Variant.Ransom.Gunra.11
Gen:Variant.Ransom.Gunra.16
Gen:Variant.Ransom.Gunra.2
Gen:Variant.Ransom.Gunra.28
Gen:Variant.Ransom.Gunra.8
Gen:Variant.Ransom.Gunra.9
Linux.Ransomware.Gunra
Trojan.Linux.Ransom.Gunra
Trojan.Ransom.Gunra