Quick Summary
AllegedExecutive Summary
The ransomware group Gunra claimed BOMOHSA as a victim, listing the company on its dark web portal on August 18, 2026. BOMOHSA is a commercial firm based in Honduras, operating with the domain bomohsa[.]com. While the specific sector of BOMOHSA is not detailed, the group’s broad targeting range, which includes Central America, suggests potential interest in a variety of industries. Gunra has shown a pattern of targeting multiple sectors including Healthcare, Technology, and Manufacturing across various geographies such as Honduras, Indonesia, and South Korea, indicating a lack of strict regional or sectoral concentration in their attacks. In the 60 days preceding this listing, Gunra claimed eight other victims. The group’s targeting has extended across diverse regions, including Honduras, Indonesia, and South Korea, with no strong regional preference. Some comparable recent victims listed by Gunra include PT All Cosmos Biotek, Siam Stabilizers and Chemicals Co. Ltd. / SSC, and Weilhotel. BOMOHSA’s location in Central America falls within Gunra’s known targeting scope, making it a plausible target for the group’s extortion activities.
Technical Analysis
A SOCRadar query into stealer-log data for the domain bomohsa[.]com revealed a severe situation, with six credentials surfacing. The compromised infrastructure includes Microsoft’s identity provider (login.live[.]com for @bomohsa[.]com accounts), Office 365 mail (smtp.office365[.]com), and a WordPress admin endpoint. Additionally, credentials for a cPanel/hosting control panel were also found. One specific account, ing****e@bomohsa[.]com, appeared in six records across the period of July 25 to August 10, 2026. The identified platforms for these credentials included identity services, mail, Shutterstock, and internal IP addresses. This pattern suggests a single workstation infection with multiple credential exfiltration sessions occurring over a period from June to August 10, 2026, indicating two months of unrotated access. The compromise of Microsoft identity and Office 365 mail, coupled with a lack of credential rotation for two months, presents a high-risk precondition for potential ransomware deployment. This scenario necessitates immediate action, regardless of whether the threat actor is Gunra directly or an initial access broker supplying credentials. Rotate all @bomohsa[.]com credentials. Enforce Multi-Factor Authentication (MFA) on Microsoft and mail infrastructure. Audit sign-in logs from June 12, 2026, onward.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.