Analysis of Gunra Ransomware Using Vulnerable Random Number Generation Function (Distributed for Linux Environments in ELF Format)
ID: 6483d2d2-6320-5275-9747-a8f62fbb4890
STIX ID: report--6483d2d2-6320-5275-9747-a8f62fbb4890
Feed Name: ASEC
Threat Score
This report analyzes the Gunra ransomware (active April 2025), detailing its command-line options, per-file and disk encryption behavior, and differences between ELF (Linux) and EXE (Windows) variants. The ELF variant uses ChaCha20 with a cryptographically weak rand()-based key/nonce generator that makes brute-force decryption feasible, while the EXE variant uses ChaCha8 with CryptGenRandom(), rendering decryption infeasible; the report includes IOCs (MD5) and AhnLab detection names.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
