gunra
Ransomware group profile
Description
Gunra is a ransomware group that emerged in June 2025, primarily motivated by financial extortion. The group targets various organizations across multiple sectors by encrypting their data and threatening to publicly release stolen information if ransoms are not paid.
Key insights
- •Employs ransomware tactics to encrypt victim data.
- •Targets a wide range of sectors, including health care and legal services.
- •Utilizes ransom notes to instruct victims to pay for decryption keys through Tor-based portals.
- •Commonly leverages data leak sites to increase pressure on victims.
- •Established persistence techniques to maintain control over compromised systems.
Threat Level & Status Breakdown
For gunra · Based on incidents in selected period
Recent activity
Monthly attack count for gunra in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for gunra
- 6d59bb6a9874b9b03ce6ab998def5b93f68dadedccad9b14433840c2c5c3a34e
- 22c47ec98718ab243f2f474170366a1780368e084d1bf6adcd60450a9289e4be
- 5530363373dfe8fa474c9394184d2c56a0682c6a178d6f1c3536a1a3796dff42
- 91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0
- a912233df115e5002f95d55ba0481e6bff798ed3
- 0b64ee06e7b34f8d44ec47ff2fbf9f10f6753103
- 4cf09f8fd5385c4b8414fb6163d831164f1f25c8
- 5677dfad26045e271272bc98be2fd24e2f6d13737850ab1d9857fd58de05e9f9
- 66c1246e8cb9befca5d129c28de10c74d3855e68
- d520d06d78afcad2e03842cb8db4622d18b92739e89dfb8dadf5743f30dcd903
- 186c77101c027a465b14cb4a74f8381e
- 75cb7eb79a5fa0d388547520c6c452c700d38659080be074d70395729a0b578e
- e75e5778e71e062ce4a7af673f0b2513854d2367fee0f01a26c0c998863bdf6e
- 6ee4a4631b61537f877e880c61536852b09b1c3f
- f95f19fd7d71f58a67bd88fe384cf2d36cc5cd45
- eae09889399fe4fb8e78b114dba0527de913d12fb1802944a88ed136e3e90577
- 136e0bf4e5fe4d4249fe9570153a0b97
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for gunra
T1486
T1486
T1490
T1490
T1562
T1562
T1047
T1047
T1059
T1059
T1078
T1078
T1547
T1547
T1021
T1021
T1080
T1080
Victims(34)
| Company | Domain | Country | Industry | Status | Discovered | |
|---|---|---|---|---|---|---|
| STAREMPIRE | starempire.com | VN Vietnam | Hospitality | Unknown | 4 days ago | |
| SOMAFIX | — | FR France | Healthcare | Unknown | 5 days ago | |
| Cablematic Dos Mil SLU | cablematic.com | FR France | Professional Services | Unknown | 12 days ago | |
| Frontier Financial Group | ffgwm.com | HK Hong Kong | Financial Services | Claimed | about 2 months ago | |
| El Ezh Building Contracting LLC | elezh.com | AE United Arab Emirates | Other | Claimed | about 2 months ago | |
| Thai Petroleum & Trading Co., Ltd. | tpt.co.th | TH Thailand | Energy & Utilities | Claimed | about 2 months ago | |
| Grupo PyD | grupopyd.com | ES Spain | Professional Services | Claimed | about 2 months ago | |
| Ipiranga Contábil | ipirangacontabil.com | BR Brazil | Professional Services | Claimed | about 2 months ago | |
| NeoDerm | neoderm.hk | HK Hong Kong | Healthcare | Claimed | about 2 months ago | |
| INCARFE S.L. | incarfe.es | ES Spain | Manufacturing | Claimed | about 2 months ago | |
| Eric Davis Dental | ericdavisdental.com | US United States | Healthcare | Claimed | about 2 months ago | |
| Ventilaciones Nerual, S.L. | ventilacionesnerual.com | ES Spain | Manufacturing | Claimed | about 2 months ago | |
| Envy Recycling | envy-recycling.cz | CZ Czech Republic | Manufacturing | Claimed | about 2 months ago | |
| VINTAGE HOMESTEAD GmbHy | vintage-homestead.de | DE Germany | Retail & E-Commerce | Claimed | about 2 months ago | |
| Diamond | le-caillebotis-diamond.fr | FR France | Manufacturing | Claimed | about 2 months ago | |
| ASPShips | aspships.com | AU Australia | Transportation | Claimed | about 2 months ago | |
| triotech.com.sg | triotech.com | SG Singapore | Technology | Claimed | about 2 months ago | |
| bkksky.com | nokair-bkksky.com | TH Thailand | Hospitality | Claimed | about 2 months ago | |
| KUKJE PHARM CO.,LTD | kukjepharm.co.kr | KR South Korea | Manufacturing | Claimed | about 2 months ago | |
| INHA University | inha.ac.kr | KR South Korea | Education | Claimed | 5 months ago |
Page 1 of 2
Affected countries(28)
Countries where this group has been reported to target or leak victims.