Gunra Ransomware: Multithreaded ChaCha20 Encryption Explained
ID: cedb0932-dda2-5658-a40a-82d163391d52
STIX ID: report--cedb0932-dda2-5658-a40a-82d163391d52
Feed Name: Picus Security Articles
Gunra (aka Golden Community) is a Conti-derived ransomware-as-a-service observed since April 2025 that performs large-scale data theft followed by fast, multi-threaded encryption of Windows and Linux systems (ChaCha20 + RSA-4096), appending .ENCRT and using double-extortion tactics; affiliates exploit FortiOS/FortiProxy authentication bypasses (CVE-2024-55591, CVE-2025-24472), leverage common post-exploitation tools (Impacket, rclone, 7-Zip), and have exfiltrated tens of terabytes to cloud/file-sharing services, with a formal RaaS program enabling wide dissemination and significant operational impact across multiple regions and critical sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
