Ransomware Group intelligence
Gunra
ActiveTrack Gunra with 62 published victims and 3 known leak locations in a single intelligence view.
Overview
Gunra is tracked by Breach House as a ransomware group with 62 published victims.
Korea, Republic of is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Up checked 1h ago | www.lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd.onion |
| Leak location 2 | Onion service | Up checked 1h ago | lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd.onion |
| Leak location 1 | Onion service | Down checked 1h ago | gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad.onion |
Top Activity Sectors (13)
- Manufacturing / Engineering 10
- Not identified 6
- Finance / Legal / Insurance 6
- Construction / Real Estate 6
- IT 5
- Retail / E-commerce 5
- Healthcare / Pharma 5
- Services 3
- Transportation / Travel / Logistics 2
- Hospitality / Food & Beverage / Tourism 1
- Education 1
- Communication / Marketing 1
- Agriculture / Food 1
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Gunra, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: gunra exploits valid local accounts harvested during discovery to gain initial access and maintain persistence across systems.
What that means: Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1059.001 PowerShell Execution
What they do: gunra executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: gunra modifies registry run keys to establish persistence by launching malicious payloads automatically on system startup.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: gunra disables antivirus tools and security software via command execution to evade detection and persistence mechanisms.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: gunra inserts junk code into legitimate binaries to obfuscate malicious functions and bypass static analysis.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: gunra deletes Volume Shadow Copy and backup artifacts via command execution to prevent data recovery and increase pressure.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: gunra scans network shares using Windows tools to identify valuable files and victim infrastructure for targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: gunra uses SMB/Windows Admin Shares for lateral movement to propagate ransomware across networked manufacturing and engineering environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1485 Data Destruction Impact
What they do: gunra performs targeted data destruction of engineering CAD files and financial records to amplify operational disruption.
What that means: Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.
-
T1486 Data Encrypted for Impact Impact
What they do: gunra encrypts victim files using custom symmetric encryption routines to maximize impact and ransom demand.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: gunra executes Service Stop commands to terminate critical services like backup agents and disrupt operational continuity.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: gunra runs commands to inhibit system recovery by destroying Volume Shadow Copies and disabling backup restoration paths.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
R3ADM3_2.txt
=======================================================================
Gunra Ransomware Group Black Hole LLC
=======================================================================
Your data has been encrypted, and we have taken copies of certain sensitive files.
This encryption was carried out for financial reasons, and a payment will be required before we can provide the tools needed to restore your data.
You will not be able to restore your data without our assistance. We can ensure full recovery if we work together.
To show that we are able to restore your files, we can decrypt a few non-critical files at no cost.
If we reach an agreement, we will keep all discussions private and delete the data we took.
Please see the contact information below for the next steps.
========================== How to Contact Us ==========================
Please download Tor Browser from the URL https://www.torproject.org/
Then install and open it.
Then connect to the URL below and log in with the given credentials.
Contact URL: http://nms.lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd.onion
Client ID: [snip]
Initial password: [snip]
R3ADM3.txt
Your data has been encrypted, and we have taken copies of certain sensitive files. This encryption was carried out for financial reasons, and a payment will be required before we can provide the tools needed to restore your data. You will not be able to restore your data without our assistance. We can ensure full recovery if we work together. To show that we are able to restore your files, we can decrypt a few non-critical files at no cost. If we reach an agreement, we will keep all discussions private and delete the data we took. Please see the contact information below for the next steps. ========================== How to Contact Us ========================== Please download Tor Browser from the URL https://www.torproject.org/ Then install and open it. Then connect to the URL below and log in with the given credentials. Contact URL: http://nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd.onion Client ID: [snip] Initial password: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (62)
Search, filter and paginate the victim timeline for Gunra. Showing 1–62 of 62.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | BOMOHSA id31823 View details | Honduras | — | — | |
|
Sector: Service Contractor | Revenue: US$ 20,000,000 |
|||||
| Ransomware | PT All Cosmos Biotek id31245 View details | Indonesia | Other | — | |
|
Allcosmos.com is an entity based in Indonesia, operating in the other sector. The company likely provides various services, given its sector classification. Allcosmos.com was listed as a ransomware victim associated with gunra |
|||||
| Ransomware | PT All Cosmos Biotek id31245 View details | Indonesia | Other | — | |
|
Sector: Agricultural Biotechnology & Fertilizer | Revenue: US$ 5,000,000 |
|||||
| Ransomware | worldtube id31222 View details | Korea, Republic of | Manufacturing / Engineering | — | |
|
Worldtube.co.kr is a South Korean company operating in the manufacturing and engineering sector. The company is based in Korea and provides various products and services related to its sector. Worldtube.co.kr was listed as a ransomware victim associated with gunra |
|||||
| Ransomware | worldtube id31222 View details | Korea, Republic of | Manufacturing / Engineering | — | |
|
Sector: Manufacturer of new automotive parts | Revenue: US$ 20,000,000 |
|||||
| Ransomware | Siam Stabilizers and Chemicals Co., Ltd. / SSC id31053 View details | Thailand | IT | — | |
|
Sakai-ssc.com is an IT company based in Thailand, providing various services within the sector. The company operates in the IT industry, offering solutions and support to clients. Sakai-ssc.com was listed as a ransomware victim associated with gunra. |
|||||
| Ransomware | Siam Stabilizers and Chemicals Co., Ltd. / SSC id31053 View details | Thailand | IT | — | |
|
Sector: chemical additives and heat stabilizer | Revenue: US$ 20,000,000 |
|||||
| Ransomware | Weilhotel id31022 View details | Malaysia | Hospitality / Food & Beverage / Tourism | — | |
|
Weilhotel.com operates in the hospitality sector in Malaysia, providing services to the food and beverage and tourism industries. The entity is involved in hotel management, offering various amenities and accommodations to its guests. Weilhotel.com was listed as a ransomware victim associated with gunra. |
|||||
| Ransomware | Weilhotel id31022 View details | Malaysia | Hospitality / Food & Beverage / Tourism | — | |
|
Sector: Hotel | Revenue: US$ 5,000,000 |
|||||
| Ransomware | Dissinger and Dissinger Law Firm id30625 View details | United States | Finance / Legal / Insurance | — | |
|
Dissingerlaw.com is a law firm based in the United States, operating within the finance and legal sector. The firm provides legal services to clients. Dissingerlaw.com was listed as a ransomware victim associated with gunra |
|||||
| Ransomware | Dissinger and Dissinger Law Firm id30625 View details | United States | Finance / Legal / Insurance | — | |
|
[AI generated] N/A |
|||||
| Ransomware | New Tiles S.L. id30385 View details | Spain | Retail / E-commerce | — | |
|
New-tiles.com operates in the retail and e-commerce sector, offering products to customers in Spain. As an e-commerce platform, it provides a range of products, likely including tiles and related home improvement items. New-tiles.com was listed as a ransomware victim associated with gunra. |
|||||
| Ransomware | New Tiles S.L. id30385 View details | Spain | Retail / E-commerce | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Pirámide Seguros id30126 View details | Venezuela, Bolivarian Republic of | Finance / Legal / Insurance | — | |
|
Segurospiramide.com is a Venezuelan company operating in the finance, legal, and insurance sectors. The company likely provides various insurance and financial services to its clients in Venezuela. Segurospiramide.com was listed as a ransomware victim associated with gunra. |
|||||
| Ransomware | Pirámide Seguros id30126 View details | Venezuela, Bolivarian Republic of | Finance / Legal / Insurance | — | |
|
[AI generated] N/A |
|||||
| Ransomware | on-us id30127 View details | Hong Kong | IT | — | |
|
On-us.com is an IT company based in Hong Kong, providing various IT services. The company operates in the IT sector, offering a range of solutions to its clients. On-us.com was listed as a ransomware victim associated with gunra |
|||||
| Ransomware | on-us id30127 View details | Hong Kong | IT | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Yuditec S.A. id30128 View details | Uruguay | IT | — | |
|
Yuditec.com is an IT company based in Uruguay, providing various services within the technology sector. As a company operating in the IT sector, yuditec.com likely offers services such as software development, consulting, and technology solutions. Yuditec.com was listed as a ransomware victim associated with gunra. |
|||||
| Ransomware | Yuditec S.A. id30128 View details | Uruguay | IT | — | |
|
[AI generated] N/A |
|||||
| Ransomware | MHE9 Logística Ltda id29825 View details | Brazil | Construction / Real Estate | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Suárez&Clavera id29826 View details | Uruguay | Construction / Real Estate | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Cambridge Law Chambers id29698 View details | Bahamas | Retail / E-commerce | — | |
|
[AI generated] N/A |
|||||
| Ransomware | STAREMPIRE id29379 View details | Viet Nam | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | SOMAFIX id29403 View details | France | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Cablematic Dos Mil SLU id29314 View details | Spain | IT | — | |
|
[AI generated] Cablematic Dos Mil SLU is a Spanish company operating in the electronics and technology distribution sector. Based in Spain, it specializes in the wholesale and retail distribution of networking equipment, cables, connectors, computer peripherals, and audiovisual accessories. The company supplies both professional and consumer markets, offering a wide catalog of hardware components and connectivity solutions across Europe, primarily through e-commerce channels. |
|||||
| Ransomware | Frontier Financial Group id28007 View details | Hong Kong | Finance / Legal / Insurance | ||
|
[AI generated] N/A |
|||||
| Ransomware | El Ezh Building Contracting LLC id28006 View details | United Arab Emirates | Retail / E-commerce | ||
|
[AI generated] N/A |
|||||
| Ransomware | Thai Petroleum & Trading Co., Ltd. id28005 View details | Thailand | Manufacturing / Engineering | ||
|
[AI generated] Thai Petroleum & Trading Co., Ltd. is a company based in Thailand operating in the petroleum and energy sector. It is involved in the trading, distribution, and supply of petroleum products and related commodities. The company serves industrial and commercial clients within Thailand and potentially across Southeast Asia. It operates within the oil and gas trading industry, contributing to the regional energy supply chain. |
|||||
| Ransomware | Grupo PyD id28004 View details | Argentina | Construction / Real Estate | ||
|
[AI generated] Grupo PyD is a Spanish consulting and human resources company operating in Spain. It specializes in personnel selection, recruitment, training, and organizational consulting services for businesses across various sectors. The firm supports companies in talent acquisition, workforce development, and HR management. Based in Spain, it serves both private and public sector clients seeking professional human capital and advisory solutions. |
|||||
| Ransomware | Ipiranga Contábil id28003 View details | Brazil | Finance / Legal / Insurance | ||
|
[AI generated] N/A |
|||||
| Ransomware | NeoDerm id28002 View details | Hong Kong | Healthcare / Pharma | ||
|
[AI generated] N/A |
|||||
| Ransomware | INCARFE S.L. id28001 View details | Spain | Manufacturing / Engineering | ||
|
[AI generated] N/A |
|||||
| Ransomware | Eric Davis Dental id28000 View details | Australia | Healthcare / Pharma | ||
|
[AI generated] Eric Davis Dental is a dental practice based in the United States. The company operates in the healthcare and dental services industry, providing a range of oral health services to patients. These typically include general dentistry, cosmetic dental procedures, and preventive care. As a private dental practice, it serves local communities and focuses on patient-centered care and dental wellness. |
|||||
| Ransomware | Ventilaciones Nerual, S.L. id27999 View details | Spain | Construction / Real Estate | ||
|
[AI generated] N/A |
|||||
| Ransomware | Envy Recycling id27998 View details | Czechia | Manufacturing / Engineering | ||
|
[AI generated] N/A |
|||||
| Ransomware | VINTAGE HOMESTEAD GmbHy id27997 View details | Germany | Retail / E-commerce | ||
|
[AI generated] N/A |
|||||
| Ransomware | Diamond id27996 View details | France | Manufacturing / Engineering | ||
|
[AI generated] N/A |
|||||
| Ransomware | ASPShips id27995 View details | Australia | Transportation / Travel / Logistics | ||
|
[AI generated] N/A |
|||||
| Ransomware | triotech.com.sg id27994 View details | Singapore | Manufacturing / Engineering | ||
|
[AI generated] Triotech is a Singapore-based technology company operating in the IT solutions and services industry. The company provides a range of technology products and services including networking, infrastructure, and IT support solutions to businesses. Serving clients primarily in Singapore, Triotech focuses on delivering integrated technology solutions to help organizations manage and optimize their IT environments efficiently. |
|||||
| Ransomware | bkksky.com id27993 View details | Thailand | Transportation / Travel / Logistics | ||
|
[AI generated] N/A |
|||||
| Ransomware | KUKJE PHARM CO.,LTD id27992 View details | Korea, Republic of | Healthcare / Pharma | — | |
|
[AI generated] KUKJE PHARM CO., LTD is a South Korean pharmaceutical company engaged in the manufacture and distribution of pharmaceutical products. The company operates within the healthcare and life sciences industry, producing medicines and related chemical compounds for both domestic and international markets. Based in South Korea, it is part of the country's established pharmaceutical manufacturing sector. |
|||||
| Ransomware | INHA University id25190 View details | Korea, Republic of | Education | ||
|
[AI generated] INHA University is a private research university located in Incheon, South Korea. It was established in 1954 and is currently known for its programs in engineering, technology, and management. The university is named after the acronym of the Independence and Nationalism sought in developing Highly skilled Authorities, highlighting its commitment to fostering leaders. |
|||||
| Ransomware | miraense.com id22697 View details | Brazil | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | hwacheon id22246 View details | Korea, Republic of | Manufacturing / Engineering | ||
|
[AI generated] Hwacheon is a South Korean company recognized as one of Asia's leading manufacturers of high-quality industrial machinery. The company's product line includes machinery for die-molding, automobile parts, machinery molds, and high-precision parts. Hwacheon’s commitment is to provide technological innovation and customer satisfaction. Overall, the company's reputation is based on quality, reliability, and innovation in the machinery industry. |
|||||
| Ransomware | Samwha Capacitor Group id22094 View details | Korea, Republic of | IT | ||
|
[AI generated] Samwha Capacitor Group, founded in 1973 in South Korea, is a global company manufacturing electronic components. Their product line includes a variety of capacitors—devices that store electrical energy. These are used in numerous industries, such as electronics, automotive, and information technology. Samwha Capacitor Group has subsidiaries in several countries and strives for technological innovation and sustainable growth. |
|||||
| Ransomware | Justicia Penal Militar id21813 View details | Colombia | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | SEGUROS AMÉRICA id21812 View details | Nicaragua | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | Seoul Guarantee Insurance id21811 View details | Korea, Republic of | Finance / Legal / Insurance | ||
|
[AI generated] Seoul Guarantee Insurance (SGI) is a South Korean company specializing in credit and guarantee insurance for businesses. It offers insurance cover for trade, construction, and small to medium-sized businesses. It also provides surety bonds, credit guarantees, and financial services. Other services include reinsurance, loan guarantees, export insurance, and retail insurance products. The company was established in 1969 and is based in Seoul, South Korea. |
|||||
| Ransomware | ACCS Le Groupe id20499 View details | Canada | Construction / Real Estate | ||
|
accslegroupe.ca is the website of ACCS, a Terrebonne, Quebec company that provides building intelligence, automation, and technology integration services. The firm says it supports building performance with operational support, system integration, and smart-building solutions for projects in commercial, institutional, and industrial real estate. Founded in 1992, ACCS also works on existing buildings and new construction, with services spanning HVAC control, security, and centralized building management. It was listed as a ransomware victim associated with gunra. |
|||||
| Ransomware | ACCS Le Groupe id21810 View details | Canada | Services | ||
|
[AI generated] ACCS Le Groupe is a French-based company specializing in the delivery of IT solutions and services. The company offers a comprehensive range of services including IT auditing, consulting, project management, and training. Their solutions are tailored to meet the specific needs of businesses across varying sectors. Additionally, ACCS Le Groupe provides infrastructures hosting, data management tools and cybersecurity measures to ensure efficient and secure business operations. |
|||||
| Ransomware | American Hospital Dubai id20450 View details | United Arab Emirates | Healthcare / Pharma | ||
|
Healthcare Service |
|||||
| Ransomware | Olho D'Água Distribuidora id20235 View details | Brazil | Services | ||
|
Water distribution and tanker truck services |
|||||
| Ransomware | Anjos Ramos id20213 View details | Brazil | Finance / Legal / Insurance | ||
|
Advocacy / Law Firm |
|||||
| Ransomware | Adria Grupa id20185 View details | Croatia | Services | ||
|
Facilities Management & Commercial Cleaning, Business Services |
|||||
| Ransomware | MG Chemicals id20107 View details | Canada | Manufacturing / Engineering | ||
|
Chemical Manufacturing, Chemicals, Petrochemicals, Glass & Gases, Manufacturing |
|||||
| Ransomware | Grupo Jorge Batista id19980 View details | Brazil | Retail / E-commerce | ||
|
E-Commerce |
|||||
| Ransomware | TOMOKU CO., LTD. id19721 View details | Japan | Communication / Marketing | ||
|
Paper/Soft Products |
|||||
| Ransomware | Bioprofarma Bagó S.A id19597 View details | Argentina | Agriculture / Food | ||
|
Pharmaceuticals |
|||||
| Ransomware | KLINGER Italy id19580 View details | Italy | Manufacturing / Engineering | ||
|
Level Gauges, valves and industrial gaskets |
|||||
| Ransomware | Varela Hermanos id19314 View details | Panama | Manufacturing / Engineering | ||
|
Beverage Manufacturing |
|||||
| Ransomware | Dar Al Teb id19313 View details | Egypt | Healthcare / Pharma | ||
|
Hospital & Healthcare |
|||||
| Ransomware | Shinko Shoji id19312 View details | Japan | Construction / Real Estate | ||
|
Real Estate |
|||||