Quick Summary
AllegedExecutive Summary
Weilhotel, a hospitality company based in Malaysia, was listed as a victim on the Gunra ransomware group’s dark web portal on July 29, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service. The presence of a Malaysian hospitality company on Gunra’s portal is notable, as it represents the only Southeast Asian and the sole hospitality sector victim identified by SOCRadar within Gunra’s recent activity. This outlier status suggests a potential deviation from the group’s typical targeting patterns or an expansion of their operational scope. In the 60 days preceding this listing, Gunra claimed seven other victims. These victims were primarily in the business services sector, with individual claims in financial services and transportation and logistics. Geographically, Gunra’s recent activity has centered around Uruguay, with single victims claimed in the United States and Hong Kong, indicating a focus on Latin America. Other recent victims with profiles similar to Weilhotel, such as consumer-facing service businesses or organizations outside Europe and North America, include Dissinger and Dissinger Law Firm, Yuditec S.A., on-us, and Pirámide Seguros. Weilhotel’s inclusion does not necessarily indicate a regional expansion by Gunra, given the limited number of total victims.
Technical Analysis
SOCRadar’s stealer-log telemetry analysis identified a significant exposure related to the weilhotel[.]com domain. The queried data returned two credential records associated with an internal, back-office portal subdomain on Weilhotel’s infrastructure. Both records were cautiously classified as external or third-party user authentications rather than employee credentials, due to the masked username format and the inability to verify corporate affiliation from the record alone. This classification suggests a potential customer account takeover or supplier risk scenario, rather than a direct corporate intrusion. A noteworthy aspect of these findings is that the same masked username appeared in both records approximately seven months apart, with log dates ranging from November 2025 to June 2026. This extended period of validity could indicate either an unrotated credential that remained active or a repeated infection of the same endpoint. For ransomware groups like Gunra, the acquisition of infostealer-harvested credentials is a common method for gaining initial access. Threat actors or initial access brokers typically source these credentials from underground marketplaces, validate them, and then use them to access systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the stealer-log evidence does not definitively confirm that Gunra utilized these specific credentials for the Weilhotel incident, the observed pattern aligns with the typical kill chain for such attacks. A critical caveat is the classification of the accounts as non-employee; if these prove to be internal accounts, the risk profile shifts towards corporate intrusion, making the seven-month persistence window a more substantial concern. The findings suggest that continued dark web and stealer-log monitoring for Weilhotel is advisable. Proactive credential hygiene checks, including password rotation and multi-factor authentication reviews for all accounts, especially those used for external or third-party access, are recommended. Monitoring alternative corporate domains and reviewing activity logs for Microsoft 365, VPNs, and remote-access portals should also be prioritized.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.