216.73.216.226

Gunra Ransomware Emerges with New DLS

· Published 24/07/2025 11:30 · Modified 24/07/2025 20:37

Export JSON

Essential information

Published
24/07/2025 11:30
Modified
24/07/2025 20:37
Tags
2025-07-24 chacha20 conti dls encryption gunra ransomware volume shadow copy
Related entities
3 observables, 1 intrusion sets (apt), 4 malware

Description

A new group called has emerged with a Dedicated Leak Site () in April 2025. 's code shows similarities to the infamous , suggesting it may be leveraging 's leaked source code. The group employs aggressive tactics, including a time-based pressure technique that forces victims to begin negotiations within five days. encrypts files using a combination of RSA and algorithms, excludes certain folders and file types from , and drops a ransom note named 'R3ADM3.txt'. The also deletes volume shadow copies to hinder recovery efforts. As the threat of grows, organizations are advised to implement robust security measures, including regular updates, backups, and user education.

External references