Gunra Ransomware: Tracing How the Attackers Moved From Linux to Windows:

Summary
About Gunra
- Active from April 2025
- Attacks targeting multinational companies in South Korea, Japan, Egypt, Panama, Italy, Argentina, and others.
Ransomware Information – ELF Format: Targeting Linux
- Checks argument values before ransomware operation - has various features
- Generates and uses a different encryption key depending on the encryption target
- Encrypts files and disks using the ChaCha20 encryption algorithm
- The encryption key is encrypted with the RSA algorithm - either appended to the end of the file or stored as a separate file
- Weak random number generation function - encryption keys and nonce values can be predicted, making decryption highly possible
Ransomware Information – EXE Format: Targeting Windows
- Uses the MurmurHash2 hashing algorithm to dynamically resolve DLL and API strings to hinder analysis
- Creates a mutex named "kjsidugiaadf99439" to prevent duplicate execution
- Uses WMI to delete volume shadow copies to prevent the recovery of encrypted files
- Generates and uses a different encryption key for each file
- Encrypts files using the ChaCha8 encryption algorithm
- The key used to encrypt a file is encrypted with the RSA algorithm - appended to the end of the file
- Encrypts files using different methods depending on the file extension and size
Introduction to the Threat Group
The Gunra ransomware group, which began its activities in April 2025, primarily targets Windows and Linux systems. It is known to carry out attacks targeting multinational companies in South Korea, Japan, Egypt, Panama, Italy, Argentina, and others.
Like other ransomware groups, Gunra ransomware encrypts files on infected systems and exfiltrates sensitive data from victim companies. If the ransom is not paid, the exfiltrated information will be disclosed.

Figure 1. Gunra ransomware group's dedicated leak site (DLS) (.onion)
According to AhnLab's analysis, the Gunra ransomware group was found to use EXE for Windows systems and ELF format for Linux systems.
ELF-format ransomware targeting Linux systems has similar encryption capabilities to EXE format ransomware targeting Windows. However, it is characterized by using commands specialized for the Linux environment to take control of the system. Recently, there has been an increasing risk of damage in Linux server environments, which has become a significant issue across all industries, requiring companies to exercise special caution.
The EXE-format ransomware targeting Windows systems created a mutex named "kjsidugiaadf99439", deleted volume shadow copies, and performed encryption in different ways depending on the extension and size of the file.