THREAT OPS › Threat News › #StopRansomware: Gunra Ransomware
#StopRansomware: Gunra Ransomware
<h2><strong>Advisory at a Glance</strong></h2> <table> <tbody> <tr> <th>Title</th> <td>#StopRansomware: Gunra Ransomware</td> </tr> <tr> <th>Original Publication</th> <td>August 10, 2026</td> </tr> <tr> <th>Executive Summary</th> <td>Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant firs
MITRE ATT&CK techniques
- Windows Management InstrumentationT1047
- OS Credential DumpingT1003
- SharepointT1213.002
- IP AddressesT1590.005
- External Remote ServicesT1133
- Steal Web Session CookieT1539
- Email CollectionT1114
- VulnerabilitiesT1588.006
- Network SniffingT1040
- Data from Cloud StorageT1530
- Native APIT1106
- Clear Command HistoryT1070.003
- Data from Local SystemT1005
- Exploit Public-Facing ApplicationT1190
- Credentials from Password StoresT1555
- Exfiltration Over Web ServiceT1567
- SMB/Windows Admin SharesT1021.002
- Protocol TunnelingT1572
- Use Alternate Authentication MaterialT1550
- Archive Collected DataT1560
- Remote ServicesT1021
- Default AccountsT1078.001
- Email AddressesT1589.002
- Command and Scripting InterpreterT1059
- Indicator RemovalT1070
- Pass the TicketT1550.003
- File and Directory DiscoveryT1083
- System Network Connections DiscoveryT1049
- Web ServiceT1102
- Financial TheftT1657
- Cloud ServicesT1021.007
- Selective ExclusionT1679
- Account ManipulationT1098
- Exfiltration Over Alternative ProtocolT1048
- Delay ExecutionT1678
- Valid AccountsT1078
- Multi-Factor AuthenticationT1556.006
- Data Encrypted for ImpactT1486
- Disable or Modify ToolsT1685
- CredentialsT1589.001
- Web Session CookieT1550.004
- Domain AccountsT1078.002
- Windows Command ShellT1059.003
- Remote Desktop SoftwareT1219.002
- Debugger EvasionT1622
- Pass the HashT1550.002
- Ingress Tool TransferT1105
- Remote Desktop ProtocolT1021.001
- NTDST1003.003
- Modify Authentication ProcessT1556
- Inhibit System RecoveryT1490
- Valid AccountsAML.T0012
- Data from Local SystemAML.T0037
- Exploit Public-Facing ApplicationAML.T0049
- Command and Scripting InterpreterAML.T0050
- OS Credential DumpingAML.T0090
- Use Alternate Authentication MaterialAML.T0091
Indicators of compromise
- 2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751sha256
- 834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1sha256
- 91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0sha256
- a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9sha256
- CVE-2024-55591cve
- CVE-2025-24472cve
- https://cve.org/CVERecord?id=CVE-2024-55591url
- https://cve.org/CVERecord?id=CVE-2025-24472url
- https://www.cve.org/CVERecord?id=CVE-2024-55591url
- https://www.cve.org/CVERecord?id=CVE-2025-24472url
- https://www.stopransomware.gov/url
- https://www.secretservice.gov/investigations/cyberincidenturl
- https://www.ic3.gov/Home/ComplaintChoiceurl
- https://www.fbi.gov/contact-us/field-officesurl
- https://www.secretservice.gov/contact/field-officesurl
- https://www.ecrm.police.go.kr/url
- https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-payingurl
- https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.htmlurl
- https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/url
- https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-lockerurl
- https://www.virustotal.com/gui/file/91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0/detailsurl
- a00f105546345756@proton.meemail
- 4569f6322bc3b22e9@proton.meemail
- ilovemycubscout@gmail.comemail
- 6449a3c1e612168526@proton.meemail
- contact@cisa.dhs.govemail
- 23.239.119.2ipv4
- 23.239.119.3ipv4
- 23.239.119.4ipv4
- 23.239.119.5ipv4
- 23.239.119.6ipv4
- 86.54.28.216ipv4
- 103.125.234.14ipv4
- 70.36.99.82ipv4
- 211.21.210.181ipv4
- 123.184.143.105ipv4
- 182.204.21.240ipv4
- 182.204.16.112ipv4
- 123.244.187.144ipv4
- 182.204.39.118ipv4
Original source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a