Friday, September 11, 2026

Gunra Ransomware Expands RaaS After Conti Locker Shift

Gunra ransomware is rapidly evolving into a more structured and dangerous cybercrime operation after shifting from a Conti-based locker to its own Ransomware-as-a-Service (RaaS) model.

First discovered in April 2025, the group initially targeted a small number of victims, but its recent operational changes have significantly increased its reach and impact across industries.

Gunra first drew attention after attacking five companies in South Korea shortly after its emergence. In its early stages, the group relied on a Conti-based ransomware variant, indicating ties to previously leaked Conti source code that many threat actors have reused.

However, Gunra has since transitioned into a fully independent operation by developing its own ransomware payload.

This shift coincided with the group adopting a RaaS model, allowing affiliates to use its tools in exchange for a share of ransom payments.

As of March 9, 2026, at least 32 organizations have been confirmed as victims of Gunra ransomware attacks.

While activity slowed during the second half of 2025, the move into the RaaS ecosystem has driven a noticeable resurgence in attacks, suggesting successful affiliate recruitment and scaling.

Analysis of S2W research, reveals a consistent activity window between 08:00 and 10:00, aligning with typical business hours in parts of Asia. However, due to limited data, attributing a specific geographic origin remains inconclusive.

Gunra maintains a low public profile and avoids excessive promotion. Instead, it operates within established dark web communities where ransomware activity is normalized. The group has been observed on forums such as RAMP, Rehub, Tierone, and Darkforums.

Gunra's DLS (Source : S2W).
Gunra’s DLS (Source : S2W).

Within these platforms, Gunra promotes its RaaS program, recruits affiliates and penetration testers, and sells stolen data from compromised organizations.

In at least one case, a user posted data from the same victim as the operator, suggesting coordination and confirming the presence of active affiliates within the ecosystem.

Gunra Ransomware

Unlike many RaaS groups, Gunra affiliates do not publicly declare their association. However, indirect evidence such as shared victim data confirms collaboration between operators and affiliates.

Further insights into Gunra ransomware infrastructure reveal a feature-rich affiliate panel. The platform includes functions for negotiation, file management, payload deployment (lock tool), handler communication, and brand customization.

Notably, Gunra allows affiliates to operate under their own ransomware branding, increasing the likelihood of new variants emerging under different names.

The operator also plays an active role in ransom negotiations, indicating centralized control over critical stages of the attack lifecycle.

The group does not enforce strict rules on target industries. Additionally, restrictions on geographic targets appear flexible and may depend on the affiliate’s location, increasing the risk of widespread and indiscriminate attacks.

Gunra’s ransomware builder supports both Windows and Linux environments, highlighting its capability to target diverse infrastructures.

The Windows variant remains consistent with previously analyzed samples, while the Linux version shows notable modifications.

These include changes to execution parameters, logging functionality, and encryption mechanisms.

Researchers have also identified cryptographic weaknesses in parts of the Linux implementation, which could potentially be leveraged for defensive analysis or decryption efforts.

Mitigations

Security experts recommend heightened vigilance due to Gunra’s expanding RaaS model and lack of targeting restrictions.

  • Continuously monitor dark web forums for emerging threats, affiliate recruitment, and leaked data.
  • Strengthen endpoint detection and response systems to identify ransomware behaviors early.
  • Apply strict access controls and patch management to reduce initial intrusion vectors.
  • Prepare incident response plans, including offline backups and recovery strategies.

Unlike other ransomware groups that avoid critical sectors such as healthcare, Gunra imposes no such limitations.

Combined with its flexible affiliate structure, this increases the potential attack surface and overall threat level.

Organizations should also monitor for new ransomware variants, as Gunra’s branding flexibility allows affiliates to launch campaigns under different identities, making detection and attribution more challenging.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News