logo

Analysis of Gunra Ransomware Using Vulnerable Random Number Generation Function (Distributed for Linux Environments in ELF Format)

ID: 6483d2d2-6320-5275-9747-a8f62fbb4890

STIX ID: report--6483d2d2-6320-5275-9747-a8f62fbb4890

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-10-21

Date Updated: 2026-04-26

Author: ATCP

...
...

This report analyzes the Gunra ransomware (active April 2025), detailing its command-line options, per-file and disk encryption behavior, and differences between ELF (Linux) and EXE (Windows) variants. The ELF variant uses ChaCha20 with a cryptographically weak rand()-based key/nonce generator that makes brute-force decryption feasible, while the EXE variant uses ChaCha8 with CryptGenRandom(), rendering decryption infeasible; the report includes IOCs (MD5) and AhnLab detection names.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.