logo

Gunra Ransomware: Multithreaded ChaCha20 Encryption Explained

ID: cedb0932-dda2-5658-a40a-82d163391d52

STIX ID: report--cedb0932-dda2-5658-a40a-82d163391d52

Feed Name: Picus Security Articles

Threat Score
78/100

Date Published: 2026-08-11

Date Updated: 2026-08-11

Author: [email protected] (Umut Bayram)

...
...

Gunra (aka Golden Community) is a Conti-derived ransomware-as-a-service observed since April 2025 that performs large-scale data theft followed by fast, multi-threaded encryption of Windows and Linux systems (ChaCha20 + RSA-4096), appending .ENCRT and using double-extortion tactics; affiliates exploit FortiOS/FortiProxy authentication bypasses (CVE-2024-55591, CVE-2025-24472), leverage common post-exploitation tools (Impacket, rclone, 7-Zip), and have exfiltrated tens of terabytes to cloud/file-sharing services, with a formal RaaS program enabling wide dissemination and significant operational impact across multiple regions and critical sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.