Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Kimsuky APT Uses Local AI Dev Environment for Cyber Espionage
August 18, 2026
Apple Patches macOS, iOS, iPadOS: 28 Vulnerabilities Fixed
August 18, 2026
Scammer Uses Claude AI to Process 100,000+ Phone Numbers for Crypto Scam Targeting
August 18, 2026
Home/Threats/Gunra Ransomware Expands RaaS Operations After Conti Shift
Threats

Gunra Ransomware Expands RaaS Operations After Conti Shift

Key Takeaways Gunra ransomware has rapidly evolved into a sophisticated Ransomware-as-a-Service (RaaS) operation, impacting dozens of organizations globally. Initially leveraging Conti-based code,...

Emy Elsamnoudy
Emy Elsamnoudy
May 15, 2026 6 Min Read
83 0

Key Takeaways

  • Gunra ransomware has rapidly evolved into a sophisticated Ransomware-as-a-Service (RaaS) operation, impacting dozens of organizations globally.
  • Initially leveraging Conti-based code, Gunra has transitioned to its own custom ransomware and a comprehensive RaaS panel, enabling broad affiliate campaigns.
  • The group maintains a low profile on dark web forums, recruiting affiliates and selling stolen data, with no strict industry or geographical targeting restrictions.
  • Defenders face challenges from Gunra’s “white-label” branding, where affiliates can launch attacks under new names, complicating attribution and threat tracking.
  • Proactive dark web monitoring and a focus on ransomware ecosystem intelligence are crucial for mitigating this evolving threat.

Within a year, the Gunra ransomware collective has escalated from a nascent threat to a formidable global challenge, compromising dozens of organizations worldwide. This evolution signifies a shift from mere data encryption to a full-fledged criminal enterprise, encompassing the sale of network access, exfiltration and leaking of sensitive files, and the active recruitment of partners to disseminate its malicious software. For cybersecurity defenders, Gunra represents a maturing and dynamic ecosystem rather than a series of isolated attacks.

Table Of Content

  • Key Takeaways
  • Gunra’s Shift to Full RaaS Operations
  • Expanding Ecosystem and Defender Response
  • What You Should Do

First detected in April 2025, Gunra initially focused its attacks on five South Korean companies. Early observations highlighted the speed and precision of these initial campaigns. At this stage, the group heavily relied on a Conti-based ransomware locker, adopting code and methodologies from the well-known, defunct Conti ransomware family. Even in its nascent phase, Gunra’s operations demonstrated meticulous planning, with activity largely coinciding with typical business hours in Asia and concentrated bursts of operator engagement during morning periods.

The group’s broad targeting strategy suggests that potential damage could affect various sectors. As S2W outlined in a report shared with Cyber Security News (CSN), this open approach also means that new ransomware brands might emerge that are technically Gunra, operating under a different name.

Gunra’s Shift to Full RaaS Operations

Over time, Gunra transitioned away from its reliance on a Conti-based locker, fully embracing a Ransomware-as-a-Service (RaaS) model. In this setup, affiliates lease the ransomware tools and infrastructure, sharing a percentage of the profits from each successful attack. As Gunra expanded into this RaaS ecosystem, analysts from S2W observed a significant resurgence in activity. After a slowdown in late 2025, new affiliates joining the program initiated their own campaigns, leading to a surge in attacks.

By March 9, 2026, a total of 32 victim organizations had been publicly confirmed, demonstrating the rapid scaling of the threat once the RaaS model was fully implemented.

S2W’s research indicates that Gunra’s operators conduct nearly all their activities through dark web forums that permit ransomware-related content. The group deliberately maintains a low public profile, preferring to engage in restricted communities such as RAMP, Rehub, Tierone, and Darkforums. Within these spaces, they actively recruit new affiliates, hire penetration testers, and offer compromised data for sale. This discreet operational strategy makes Gunra more challenging to track but also signals a deliberate, long-term business model rather than opportunistic, short-term attacks.

Gunra's DLS (Source - S2W)
Gunra’s DLS (Source – S2W)

The broader impact of Gunra is not confined to specific industries or geographical regions, as the group does not impose strict limitations on its partners’ targeting. Unlike some RaaS programs that explicitly avoid critical sectors like healthcare or infrastructure, Gunra’s internal policies do not list prohibited industries. Any geographical restrictions appear to be flexible and often tied to the affiliate’s operational location.

A pivotal factor in Gunra’s expanded RaaS operations was its move from a Conti-based locker to its own proprietary ransomware. Initially, using established Conti code provided the operators with a quick launchpad for attacks but limited their ability to customize tools and panel features. By developing their own ransomware and integrating it into a hosted panel, Gunra gained comprehensive control over all aspects of their operation, from ransomware build options to victim negotiation workflows. The S2W report details the technical aspects of this shift, which allowed for greater operational flexibility and scalability.

Under the RaaS model described by S2W, Gunra offers affiliates a web-based panel to manage their attacks, monitor victims, and process payments. This sophisticated dashboard includes features like “Negotiation,” “Files,” “Lock Tool,” “Handler,” and “Brand Setting,” streamlining affiliate operations. Notably, the core Gunra operators actively participate in victim negotiations, suggesting a centralized team oversees the most critical aspects of each extortion attempt.

Gunra’s ransomware builder supports both Windows and Linux systems, enabling affiliates to generate payloads tailored to their target environments. S2W’s analysis reveals that the Windows builds align with earlier samples, while the Linux builds have undergone significant updates, including changes to execution parameters, logging mechanisms, and encryption logic. Furthermore, the Linux builds have addressed previously identified cryptographic weaknesses, indicating that the group is continuously refining its code, patching vulnerabilities, and optimizing performance based on ongoing analysis.

As the RaaS offering matured, Gunra’s presence on the dark web became more organized. Operators promote their program on forums specializing in ransomware and data leaks, favoring a discreet approach over aggressive marketing. They rely on word-of-mouth and private communications to onboard new partners. S2W researchers successfully identified at least one user believed to be a Gunra affiliate, based on that user posting data from the same victim as the core operator, which points to a growing network of semi-autonomous actors.

Expanding Ecosystem and Defender Response

Gunra’s internal guidelines do not impose strict limitations on target industries, significantly broadening the potential threat surface for organizations of all sizes. Any country-specific prohibitions are flexibly applied, often based on the affiliate’s geographical location, granting partners considerable autonomy in selecting targets that align with their comfort levels or regional access. Furthermore, the “Brand Setting” feature allows affiliates to conduct attacks under their own custom ransomware brand, even though the underlying code and infrastructure belong to Gunra.

This “white-label” model means that cybersecurity defenders may encounter new ransomware variants that are, in fact, Gunra operating under a different guise, sharing common infrastructure and overlapping attack techniques. As the number of affiliates grows, the ecosystem can rapidly spawn multiple distinct brands, each potentially featuring its own leak site, extortion methodology, and victim pool. For security teams, this phenomenon complicates threat attribution and increases the risk of mistaking a “new” threat for a re-branded version of an existing one.

What You Should Do

  • Enhance Dark Web Visibility: Proactively monitor ransomware-friendly dark web forums and communities (e.g., RAMP, Rehub, Tierone, Darkforums) for discussions related to Gunra and its affiliates. This can provide early warnings of targeting intentions in specific sectors or regions, and reveal when stolen data from your organization might be offered for sale.
  • Prioritize Critical Sector Vigilance: Given Gunra’s lack of strict industry exclusions, critical infrastructure entities, healthcare providers, and other essential services must maintain heightened vigilance and robust defensive postures.
  • Track Emerging Ransomware Brands: Be suspicious of new ransomware names that appear suddenly on the dark web without a clear lineage, especially if they exhibit technical markers or behavioral patterns consistent with Gunra. Develop capabilities to map these relationships to understand underlying attack structures.
  • Integrate Threat Intelligence: Combine traditional security controls (patching, strong access controls, endpoint detection and response) with specialized threat intelligence focusing on ransomware ecosystems. Subscribe to intelligence feeds and engage in information sharing to stay current on evolving RaaS tactics.
  • Foster a Proactive Security Posture: Treat Gunra as an evolving ecosystem rather than a static malware family. Continuously adapt defensive strategies to anticipate new affiliate campaigns and re-branded attacks.

Indicators of Compromise (IoCs):-

Type Indicator Description
URL https://s2w.inc/en/resource/detail/10571/5 S2W Gunra ransomware report resource page
URL https://s2w.inc/en/resource/detail/10572/5 S2W Gunra ransomware activity and panel analysis
URL <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7a53b693-4224-425a-9121-747471c5c7ae/Gunra-Ransomware-Expands-RaaS-Operations-After-Shifting-From-Conti-Based-Locker.pdf?AWSAccessKeyId=ASIA2F3EMEYERWFS2PKH&Signature=Ac5ibbjhoiz3SoWZ5eyGZjy%2FY0%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEK%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIF3qajxl%2FhNKOnyak7k4i3oYXZ6WeNwvxRJFFrHgvsy3AiAzLiqzosJXRTTq6Q4lPcjjw0ySi8sgOhLPekmaclsVgyrzBAh4EAEaDDY5OTc1MzMwOTcwNSIM38WZA9VskQ%2B%2BdUU5KtAEcSpBrdJyZa3UlJlhYHbhce2TnMr9bmJUp%2FufWgkByIufeB%2FOarxLsyP2Hd%2FmBKDBeN1zo7Q5UQ1qXdbBjs7XcATo05PuFJPZSqjmanBMpLpjGyAVMNU5%2FuCF7joTwi47wAPvEV4HREnjDW6PIo4AvKfMSDZ8t0NUtLbJESeYpRgxFphmetxpJSlWzLjyZh956P%2Fz9pGU%2Bkws6L%2BlbXrpAGsmJryIPJyf58IcKk7TkIlNustFiiaXIMfY5JGmHwg2cRBgPxMK32wtMB

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarePatchransomwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Shai-Hulud Worm Steals Cloud Credentials From Developers

Next Post

Critical OpenClaw Chain Flaws Expose 245,000 AI Agent Servers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OpenAI Warns AI Models Can Automate Cyberattacks and Exploit Vulnerabilities
August 18, 2026
CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks
August 18, 2026
Shadow hVNC Tool Grants Covert Remote Access, Bypassing User Detection
August 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us