Gunra Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
May 15, 2026
Last Seen
July 30, 2026

Gunra is a ransomware_group tracked by ThreatCluster, appearing in 2 threat clusters built from 5 intelligence report mentions.

Gunra is a ransomware_group tracked across 2 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed May 15, 2026; most recent activity July 30, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • State Hackers Made South Korea's Mandatory Banking Software Into Zero — Techtimes · July 30, 2026
  • Operation Double Barrel (The Relationship Between a State — Lazarus.Day · July 30, 2026
  • [Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) — Asec.Ahnlab · July 29, 2026
  • Gunra Ransomware Expands RaaS Operations After Shifting From Conti — Cybersecuritynews · May 15, 2026
  • Gunra Ransomware Expands RaaS After Conti Locker Shift — Gbhackers · May 15, 2026

Frequently asked questions

What is Gunra?

Gunra is a ransomware_group tracked by ThreatCluster, appearing in 2 threat clusters built from 5 intelligence report mentions.

Is Gunra still active?

The most recent intelligence report mentioning Gunra on ThreatCluster is dated July 30, 2026. Activity was first observed May 15, 2026, giving a tracked span from then to July 30, 2026.

What is Gunra associated with?

Across ThreatCluster reporting, Gunra most frequently co-occurs with Lazarus, Malware, Phishing, Ransomware, Supply Chain Attack, among 12 tracked related entities.

What are the latest developments involving Gunra?

The most significant recent cluster is “Operation Double Barrel: State-Sponsored Exploitation of Korean Financial Software” (3 articles · Updated July 30, 2026). Gunra appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on Gunra?

Gunra appears in 5 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown