Gunra Ransomware

Malware

Gunra ransomware, first identified in April 2025, has already compromised companies in the pharmaceutical, industrial and real estate sectors in countries including Japan, Egypt, Panama, Italy and Argentina. The program uses a double extortion strategy, in which sensitive data is extracted before encryption. If the victim refuses to pay the ransom, the operators threaten to publish the stolen data on underground forums.

Gunra is derived from the Conti ransomware code , but features significant improvements in evasion and persistence. After infection, it collects information about the environment, deletes shadow copies via WMI, scans the system, and injects code into trusted processes.

Incidents Caused by this Malware

Threat Actors Known to use this Malware

No threat actors identified