Gunra Ransomware Builds a New Attack Network Through RaaS
ID: 2cceced4-9d72-5fea-9a50-e82011963c43
STIX ID: report--2cceced4-9d72-5fea-9a50-e82011963c43
Feed Name: The Cyber Express
Gunra is an active double-extortion ransomware operation — derived from leaked Conti source code — that has expanded into a formal RaaS affiliate program targeting Windows and Linux environments globally. Operators exploit internet-facing VPN/firewall vulnerabilities (including CVE-2024-55591 and CVE-2025-24472), perform large-scale data exfiltration (tens of terabytes) to cloud and file-sharing services, encrypt files using ChaCha20 and RSA-4096 (observed .ENCRT and .CRYPT extensions), and publish stolen data on a leak site; US and international agencies advise immediate patching of exposed systems, network segmentation, immutable offline backups, MFA, and AD/account auditing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
