Gunra is a ransomware-as-a-service operation first observed in April 2025. It emerged as a double-extortion ransomware threat derived from leaked Conti source code, later expanding into a structured affiliate program by early 2026 and at times operating under the alias Golden Community. The group initially focused on South Korean victims before expanding into a broader international campaign affecting government, critical infrastructure, and commercial organizations across multiple regions. Gunra commonly gains initial access by exploiting known vulnerabilities in internet-facing edge infrastructure, especially firewall, VPN, SSL-VPN, and remote-access appliances, including Fortinet vulnerabilities CVE-2024-55591 and CVE-2025-24472. Reported intrusions also include abuse of default credentials, credential exposure on VPN gateways, SSH-based access, phishing, and recruitment of penetration testers or other access brokers to supply enterprise footholds. In some cases, the actors intercepted VPN traffic, harvested credentials and session material, hijacked sessions, and modified authentication logic on VDI portals to bypass multifactor authentication. Post-compromise tradecraft includes persistence through remote administration and tunneling utilities, internal reconnaissance, credential dumping, theft of reusable authentication material, SMB- and RDP-based lateral movement, and deployment using stolen privileged credentials. Gunra has been observed using Impacket tooling, OpenSSH tunneling, and anti-forensic measures such as deleting logs and clearing command history. The operation steals data before encryption, including documents, databases, internal communications, and cloud-hosted enterprise data from collaboration platforms, then threatens publication on a dedicated leak site if payment is not made. Ransom negotiations are conducted through Tor-based infrastructure, and ransom demands have reportedly reached tens of millions of dollars. Gunra supports both Windows and Linux environments. Its ransomware has been reported to append an ENCRT-style extension to encrypted files and drop a ransom note directing victims to negotiation channels. Researchers have also identified a weakness in the Linux variant's random number generation that may allow key reconstruction and file recovery in some cases. Victim sectors reported for Gunra include healthcare, financial services, manufacturing, transportation, utilities, government, media, retail, academia, nonprofit and professional services, and other critical infrastructure environments. Public reporting also notes technical overlap between some Gunra intrusions and North Korea-linked tradecraft associated with Lazarus-related activity in South Korea, including shared infrastructure or tooling in parallel campaigns, but Gunra itself has not been conclusively attributed as a North Korean state actor. The dominant characterization remains that of a financially motivated ransomware enterprise with affiliate-driven operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The attacks hinge around two Fortinet vulnerabilities, CVE-2024-55591 and CVE-2025-24472, which exploit scheduled tasks on compromised FortiOS firewall devices to forge a new, malicious persistent user with super user privileges and a hard-coded password.
The attacks hinge around two Fortinet vulnerabilities, CVE-2024-55591 and CVE-2025-24472, which exploit scheduled tasks on compromised FortiOS firewall devices to forge a new, malicious persistent user with super user privileges and a hard-coded password.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service operation conducting double-extortion attacks. Affiliates exploit known vulnerabilities in internet-facing devices, exfiltrate data, encrypt systems, and threaten to publish stolen files on a leak site if victims do not pay.
Mentioned only in passing as a growing ransomware threat in unrelated other news.
Ransomware-as-a-service group exploiting Fortinet vulnerabilities and weak/default credentials for initial access, then using persistence, lateral movement, stealthy data exfiltration from Microsoft 365, and double-extortion against victims across multiple critical sectors.
A ransomware operation that emerged in South Korea, initially used ransomware based on leaked Conti source code, later developed its own malware, and evolved into a ransomware-as-a-service model with affiliates. It uses double-extortion tactics and targets both Windows and Linux environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.