Gunra — Ransomware Profile
Gunra is a financially motivated ransomware group that emerged in April 2025, using double-extortion tactics against real estate, pharmaceuticals, and manufacturing sectors across Japan, Egypt, Panama, Italy, and Argentina, deploying separate Windows and Linux variants with a strict five-day payment deadline.Also tracked as
Golden Community
IntelFusions coverage (3)
- FBI and CISA warn of Gunra ransomware hitting hospitals 2026-08-10 · Ransomware
- Korean firms hit by backdoor tied to North Korean hackers 2026-08-06 · Nation-State
- Hacked Korean websites pushed spy backdoors and Gunra ransomware 2026-07-30 · Nation-State
Tools & malware
- Gunra Ransomware Ransomware
Recent claimed victims
- Blanco & Etcheverry 2026-09-04
- Occidental 2026-09-04
- BOMOHSA 2026-08-18
- PT All Cosmos Biotek 2026-08-05
- worldtube 2026-08-04
- Siam Stabilizers and Chemicals Co., Ltd. / SSC 2026-07-30
- Weilhotel 2026-07-29
- Dissinger and Dissinger Law Firm 2026-07-16
- New Tiles S.L. 2026-07-10
- on-us 2026-06-30
- Pirámide Seguros 2026-06-30
- Yuditec S.A. 2026-06-30
- Suárez&Clavera 2026-06-12
- MHE9 Logística Ltda 2026-06-12
- Cambridge Law Chambers 2026-06-09
- STAREMPIRE 2026-05-30
- SOMAFIX 2026-05-29
- Cablematic Dos Mil SLU 2026-05-22
- VINTAGE HOMESTEAD GmbHy 2026-04-08
- ASPShips 2026-04-08
- bkksky.com 2026-04-08
- NeoDerm 2026-04-08
- Frontier Financial Group 2026-04-08
- Triotech 2026-04-08
- El Ezh Building Contracting LLC 2026-04-08
Vendor research
- the original analysis AhnLab ASEC
- the original advisory CISA
- Gunra Ransomware - A Brief Analysis CYFIRMA