Threat Group Profile
gunra
● Active — last 30 days
Victim claims
32
First seen
Mar 2026
Last activity
18 Aug 2026
Tracked since
Apr 2025
Group overview
Gunra is a financially motivated ransomware group that emerged in April 2025, using double-extortion tactics against real estate, pharmaceuticals, and manufacturing sectors across Japan, Egypt, Panama, Italy, and Argentina, deploying separate Windows and Linux variants with a strict five-day payment deadline.
Preferred targets
Business Services · 6
Manufacturing · 5
Healthcare · 4
Financial Services · 2
Transportation/Logistics · 2
Construction · 2
Most targeted countries
ES · 4
HK · 3
TH · 3
UY · 2
BR · 2
FR · 2