Active ransomware operator
← All groupsgunra
36 victims indexed · first seen 1 year ago · last activity 1 month ago
At a glance
- Status
- active
- First seen
- 1 year ago
- Last activity
- 1 month ago
- Onion sites
- 6 known endpoints
- Primary sector
- Manufacturing · 6 hits
About
References
6 linksExternal sources curated by the MISP threat-intel community.
- ransomlook.io/group/gunra
- trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html
- darkreading.com/threat-intelligence/nimble-gunra-ransomware-linux-variant
- industrialcyber.co/ransomware/cyfirma-warns-of-gunra-ransomware-surge-targeting-critical-infrastructure-using-double-extortion
- watchguard.com/wgrd-security-hub/ransomware-tracker/gunra
- theravenfile.com/2025/09/23/gunra-ransomware-what-you-dont-know/
Timeline
7 monthsTop countries
Top sectors
MITRE ATT&CK
5 techniques · 3 tacticsTactics
Recent victims
Loading…
Onion infrastructure
6 known- http://6oeuvb4fq65xlrft2ezxjmkeqnu7oafbsevrr3ocer27wft6ivvhstqd.onion
- http://gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad.onion
- http://myeli53ogsryjg2kob4xqxtwkr5oc5zj7jr5fcfizpytwe566k5thxyd.onion
- http://raas.lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd.onion
- http://ryrw2ojab62yij4y33ssfgvm2d2vwt3tcqetu6qmpwznqhooqxz3wpqd.onion
- http://tgsst34i6z4mwdj2kpigixxb3k3xfz7xhuqnsowvfvyu3snm6nv4s5ad.onion
Source
Updated 1 month agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
