Gunra is a ransomware_group tracked by ThreatCluster, appearing in 2 threat clusters built from 5 intelligence report mentions.
Gunra is a ransomware_group tracked across 2 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed May 15, 2026; most recent activity July 30, 2026.
From 2025 to mid-2026, a state-sponsored threat group exploited vulnerabilities in Korean financial security software, utilizing watering hole attacks and spear phishing to deploy backdoors named Struggle and Brandoor.…
The Gentlemen, a ransomware-as-a-service (RaaS) group, has emerged as a significant threat since its inception in mid-2025, with 332 reported victims in the first five months of 2026. They leverage Fortinet and Cisco…
Gunra is a ransomware_group tracked by ThreatCluster, appearing in 2 threat clusters built from 5 intelligence report mentions.
The most recent intelligence report mentioning Gunra on ThreatCluster is dated July 30, 2026. Activity was first observed May 15, 2026, giving a tracked span from then to July 30, 2026.
Across ThreatCluster reporting, Gunra most frequently co-occurs with Lazarus, Malware, Phishing, Ransomware, Supply Chain Attack, among 12 tracked related entities.
The most significant recent cluster is “Operation Double Barrel: State-Sponsored Exploitation of Korean Financial Software” (3 articles · Updated July 30, 2026). Gunra appears across 2 threat clusters in total, listed above with sources.
Gunra appears in 5 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.