Description
Gunra is a ransomware as a service operation that emerged in April 2025 and builds on the leaked source code of the Conti ransomware. It exfiltrates business data before encrypting files with ChaCha20 and RSA-4096 cryptography, appends the .ENCRT extension, and drops ransom notes that direct victims to a Tor based negotiation portal under a five day deadline. Campaigns have targeted critical infrastructure, healthcare, pharmaceuticals, manufacturing, and real estate across Windows and Linux environments.
Stats
- First seen
- June 2025
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Linux.Ransom.Gunra.1 |
| Gen:Variant.Ransom.Gunra.11 |
| Gen:Variant.Ransom.Gunra.16 |
| Gen:Variant.Ransom.Gunra.2 |
| Gen:Variant.Ransom.Gunra.28 |
| Gen:Variant.Ransom.Gunra.8 |
| Gen:Variant.Ransom.Gunra.9 |
| Linux.Ransomware.Gunra |
| Trojan.Linux.Ransom.Gunra |
| Trojan.Ransom.Gunra |