logo

Gunra Ransomware Evolves From Conti-Based Locker Into RaaS Operation

ID: 1abebc81-2e59-595c-ab46-7c11b51241f6

STIX ID: report--1abebc81-2e59-595c-ab46-7c11b51241f6

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Varshini

...
...

The report describes Gunra, a ransomware group that evolved into a Ransomware-as-a-Service platform after replacing Conti-based code with a custom encryptor; it has claimed 32 victims by March 2026, recruits affiliates on dark web forums, provides a feature-rich affiliate panel (including white‑labeling and negotiation support), and upgraded its Linux payloads—raising the risk to organizations worldwide, notably because the operation permits attacks on critical infrastructure and enables affiliates to rebrand malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.