Gunra Ransomware Expands RaaS After Conti Locker Shift
ID: d3b2f005-45fd-59c8-acbc-c6d715c95b26
STIX ID: report--d3b2f005-45fd-59c8-acbc-c6d715c95b26
Feed Name: GBHackers
Gunra is a rapidly evolving ransomware group that moved from using Conti-derived code to operating an independent Ransomware-as-a-Service (RaaS), enabling affiliates to deploy customized Windows and Linux ransomware. Since its discovery in April 2025, at least 32 organizations have been confirmed victims; the group recruits on dark web forums, supports affiliate branding, and shows flexible targeting without industry or geographic restrictions, increasing its scale and risk. The report highlights an affiliate panel with negotiation and deployment features, observable activity windows, and suggests mitigations including EDR, patching, backups, and dark web monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
